VendorsIBMjazz_reporting_serviceall versions
Vulnerabilities

IBM Jazz Reporting Service

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2016-6047
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2017-02-01 · Modified
5.4EPSS 0.005
CVE-2016-6054
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2017-02-01 · Modified
5.4EPSS 0.005
CVE-2017-1490
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
Published 2017-09-14 · Modified
5.3EPSS 0.010
CVE-2017-1340
IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.
Published 2017-11-01 · Modified
5.0EPSS 0.010
CVE-2017-1370
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
Published 2017-07-31 · Modified
4.9EPSS 0.012
CVE-2024-25052
IBM Jazz Reporting Service information disclosure
Published 2024-06-13 · Modified
4.4EPSS 0.002
CVE-2019-4047
IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.
Published 2019-04-29 · Modified
4.3EPSS 0.015
CVE-2017-1157
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.
Published 2017-07-05 · Modified
4.3EPSS 0.010
CVE-2016-5898
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
Published 2017-02-01 · Modified
4.3EPSS 0.009
CVE-2015-7469
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.
Published 2016-01-17 · Modified
4.3EPSS 0.009
CVE-2015-7468
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.
Published 2016-01-17 · Modified
4.3EPSS 0.009
CVE-2015-7466
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
Published 2016-01-10 · Modified
4.0EPSS 0.008
CVE-2025-1823
IBM Jazz Reporting Service Denial of Service
Published 2026-02-04 · Analyzed
3.5EPSS 0.002
CVE-2025-2134
IBM Jazz Reporting Service Denial of Service
Published 2026-02-04 · Analyzed
3.5EPSS 0.002
CVE-2025-27550
IBM Jazz Reporting Service Information Disclosure
Published 2026-02-04 · Analyzed
3.5EPSS 0.002
← Prev2 / 2