PT-2016-3788 · Ibm · Ibm Jazz Reporting Service
Publicado
2016-01-10
·
Atualizado
2016-01-12
·
CVE-2015-7465
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Jazz Reporting Service (JRS) version 6.0 before 6.0.0-Rational-CLM-ifix005
Description
A cross-site request forgery (CSRF) issue in the Lifecycle Query Engine (LQE) of IBM Jazz Reporting Service (JRS) allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Recommendations
For IBM Jazz Reporting Service (JRS) version 6.0 before 6.0.0-Rational-CLM-ifix005, update to version 6.0.0-Rational-CLM-ifix005 or later to resolve the issue. As a temporary workaround, consider restricting access to the LQE component to minimize the risk of exploitation.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Jazz Reporting Service