CVE-2015-7469
- EPSS 0.12%
- Veröffentlicht 17.01.2016 05:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
CVE-2015-7468
- EPSS 0.12%
- Veröffentlicht 17.01.2016 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
CVE-2015-7467
- EPSS 0.17%
- Veröffentlicht 17.01.2016 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML vi...
- EPSS 0.19%
- Veröffentlicht 10.01.2016 03:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directo...
CVE-2015-7465
- EPSS 0.11%
- Veröffentlicht 10.01.2016 03:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests t...