PT-2024-20720 · Ibm · Ibm Jazz Reporting Service
Published
2024-06-13
·
Updated
2024-08-07
·
CVE-2024-25052
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Jazz Reporting Service version 7.0.3
Description
The issue concerns the storage of user credentials in plain clear text, which can be accessed by an admin user.
Recommendations
For IBM Jazz Reporting Service version 7.0.3, consider restricting admin access to minimize the risk of credential exposure until a fix is available.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Jazz Reporting Service