4.9

CVE-2017-1370

IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Jazz Reporting Service Version 5.0
Ibm ≫ Jazz Reporting Service Version 5.0.1
Ibm ≫ Jazz Reporting Service Version 5.0.2
Ibm ≫ Jazz Reporting Service Version 6.0
Ibm ≫ Jazz Reporting Service Version 6.0.1
Ibm ≫ Jazz Reporting Service Version 6.0.2
Ibm ≫ Jazz Reporting Service Version 6.0.3
Ibm ≫ Jazz Reporting Service Version 6.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-209 Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

http://www.ibm.com/support/docview.wss?uid=swg22005868
Vendor Advisory
http://www.securityfocus.com/bid/99954
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/126863
Vendor Advisory
VDB Entry