VendorsIBMjazz_reporting_service7.0.2
Vulnerabilities

IBM Jazz Reporting Service 7.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-25051
IBM Jazz Reporting Service insufficient session expiration
Published 2025-04-02 · Analyzed
7.2EPSS 0.004
CVE-2021-20535
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
Published 2021-05-13 · Modified
6.5EPSS 0.005
CVE-2020-4933
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.
Published 2021-02-18 · Modified
5.4EPSS 0.006