VulnerabilityModified
CVE-2017-1370
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page.
MEDIUM 4.9EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- ibm/jazz reporting service
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22005868Vendor Advisory
- http://www.securityfocus.com/bid/99954Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126863VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22005868Vendor Advisory
- http://www.securityfocus.com/bid/99954Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126863VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.