Skip to main content

Vendor/product archive

ibm / jazz_reporting_service CVEs

Beta · best-effort

55 CVEs tagged to ibm / jazz_reporting_service1 Critical, 6 High, 44 Medium, 4 Low, 0 Unrated.

CVE-2025-2134

Published Feb 4, 2026

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27550

Published Feb 4, 2026

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1823

Published Feb 4, 2026

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resourc…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-20535

Published May 13, 2021

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized reques…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4718

Published Nov 19, 2020

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4541

Published Aug 10, 2020

IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4539

Published Aug 10, 2020

IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4533

Published Aug 10, 2020

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4419

Published May 28, 2020

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4651

Published Jan 9, 2020

IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-4497

Published Oct 1, 2019

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4495

Published Oct 1, 2019

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4494

Published Oct 1, 2019

IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4184

Published May 29, 2019

IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alterin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4047

Published Apr 29, 2019

IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2004

Published Apr 29, 2019

IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1918

Published Jan 8, 2019

IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1639

Published Nov 16, 2018

The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileg…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1363

Published Apr 25, 2018

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1750

Published Apr 25, 2018

IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1340

Published Nov 1, 2017

IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 12…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1490

Published Sep 14, 2017

An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 55 CVEsPage 1 of 3