CVE-2016-0317

MEDIUM

IBM Jazz Reporting Service <6.0.1 - CSRF

Title source: llm

Description

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-284
Status published

Affected Products (3)

ibm/jazz_reporting_service
ibm/jazz_reporting_service
n/a/n/a

Timeline

Published Nov 25, 2016
Tracked Since Feb 18, 2026