3.5

CVE-2025-27550

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmJazz Reporting Service Version7.0.3 Update-
IbmJazz Reporting Service Version7.0.3 Updateifix001
IbmJazz Reporting Service Version7.0.3 Updateifix002
IbmJazz Reporting Service Version7.0.3 Updateifix003
IbmJazz Reporting Service Version7.0.3 Updateifix004
IbmJazz Reporting Service Version7.0.3 Updateifix005
IbmJazz Reporting Service Version7.0.3 Updateifix006
IbmJazz Reporting Service Version7.0.3 Updateifix007
IbmJazz Reporting Service Version7.0.3 Updateifix008
IbmJazz Reporting Service Version7.0.3 Updateifix009
IbmJazz Reporting Service Version7.0.3 Updateifix010
IbmJazz Reporting Service Version7.0.3 Updateifix011
IbmJazz Reporting Service Version7.0.3 Updateifix012
IbmJazz Reporting Service Version7.0.3 Updateifix013
IbmJazz Reporting Service Version7.0.3 Updateifix014
IbmJazz Reporting Service Version7.0.3 Updateifix015
IbmJazz Reporting Service Version7.0.3 Updateifix016
IbmJazz Reporting Service Version7.0.3 Updateifix017
IbmJazz Reporting Service Version7.0.3 Updateifix018
IbmJazz Reporting Service Version7.0.3 Updateifix019
IbmJazz Reporting Service Version7.0.3 Updateifix020
IbmJazz Reporting Service Version7.1 Update-
IbmJazz Reporting Service Version7.1 Updateifix001
IbmJazz Reporting Service Version7.1 Updateifix002
IbmJazz Reporting Service Version7.1 Updateifix003
IbmJazz Reporting Service Version7.1 Updateifix004-sr1-base
IbmJazz Reporting Service Version7.1 Updateifix005
IbmJazz Reporting Service Version7.1 Updateifix006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.