PT-2016-4143 · Ibm · Ibm Jazz Reporting Service

Published

2016-11-25

·

Updated

2016-11-29

·

CVE-2016-0318

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Jazz Reporting Service versions 6.0 through 6.0.1 before 6.0.1 iFix006
Description The issue allows remote attackers to obtain access by leveraging an unattended workstation due to the failure of the Lifecycle Query Engine (LQE) to destroy a Session ID upon a logout action.
Recommendations For IBM Jazz Reporting Service versions 6.0 through 6.0.1, apply iFix006 to resolve the issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0318

Affected Products

Ibm Jazz Reporting Service