3.5

CVE-2025-27550

IBM Jazz Reporting Service Information Disclosure

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update -
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix001
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix002
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix003
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix004
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix005
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix006
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix007
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix008
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix009
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix010
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix011
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix012
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix013
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix014
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix015
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix016
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix017
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix018
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix019
Ibm ≫ Jazz Reporting Service Version 7.0.3 Update ifix020
Ibm ≫ Jazz Reporting Service Version 7.1 Update -
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix001
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix002
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix003
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix004-sr1-base
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix005
Ibm ≫ Jazz Reporting Service Version 7.1 Update ifix006
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.107
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

https://www.ibm.com/support/pages/node/7258083
Vendor Advisory