CVE-2015-7469

MEDIUM

IBM Jazz Reporting Service <6.0.0-Rational-CLM-ifix005 - Auth Bypass

Title source: llm
STIX 2.1

Description

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21972485

Scores

CVSS v3 4.3
EPSS 0.0089
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-264
Status published
Products (4)
ibm/jazz_reporting_service 5.0
ibm/jazz_reporting_service 5.0.1
ibm/jazz_reporting_service 5.0.2
ibm/jazz_reporting_service 6.0
Published Jan 17, 2016
Tracked Since Feb 18, 2026