Improper Neutralization of Special Elements in Output Used by a Downstream Component in Jazz Reporting Service - CVE-2015-7466
Published: January 10, 2016 / Updated: August 9, 2020
Jazz Reporting Service
Detailed vulnerability description
The vulnerability allows a remote authenticated user to manipulate data.
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.