3.5

CVE-2025-1823

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmJazz Reporting Service Version7.0.3 Update-
IbmJazz Reporting Service Version7.0.3 Updateifix001
IbmJazz Reporting Service Version7.0.3 Updateifix002
IbmJazz Reporting Service Version7.0.3 Updateifix003
IbmJazz Reporting Service Version7.0.3 Updateifix004
IbmJazz Reporting Service Version7.0.3 Updateifix005
IbmJazz Reporting Service Version7.0.3 Updateifix006
IbmJazz Reporting Service Version7.0.3 Updateifix007
IbmJazz Reporting Service Version7.0.3 Updateifix008
IbmJazz Reporting Service Version7.0.3 Updateifix009
IbmJazz Reporting Service Version7.0.3 Updateifix010
IbmJazz Reporting Service Version7.0.3 Updateifix011
IbmJazz Reporting Service Version7.0.3 Updateifix012
IbmJazz Reporting Service Version7.0.3 Updateifix013
IbmJazz Reporting Service Version7.0.3 Updateifix014
IbmJazz Reporting Service Version7.0.3 Updateifix015
IbmJazz Reporting Service Version7.0.3 Updateifix016
IbmJazz Reporting Service Version7.0.3 Updateifix017
IbmJazz Reporting Service Version7.0.3 Updateifix018
IbmJazz Reporting Service Version7.0.3 Updateifix019
IbmJazz Reporting Service Version7.0.3 Updateifix020
IbmJazz Reporting Service Version7.1 Update-
IbmJazz Reporting Service Version7.1 Updateifix001
IbmJazz Reporting Service Version7.1 Updateifix002
IbmJazz Reporting Service Version7.1 Updateifix003
IbmJazz Reporting Service Version7.1 Updateifix004-sr1-base
IbmJazz Reporting Service Version7.1 Updateifix005
IbmJazz Reporting Service Version7.1 Updateifix006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
psirt@us.ibm.com 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.