IBM Jazz Reporting Service
cpe:2.3:a:ibm:jazz_reporting_service:*:*:*:*:*:*:*
- >= 7.1, <= 7.1iFix006
- >= 7.0.3, <= 7.0.3iFix020
An information disclosure vulnerability has been identified in IBM Jazz Reporting Service, specifically within the Lifecycle Query Engine (LQE) SPARQL endpoints. This vulnerability could allow an authenticated user on the host network to access sensitive information about other projects stored on the server. The issue affects IBM Jazz Reporting Service versions 7.1 through 7.1iFix006 and 7.0.3 to 7.0.3iFix020.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information about projects on the server, potentially allowing for misuse or unauthorized actions related to that information.
Users are advised to upgrade to IBM Jazz Reporting Service version 7.1iFix007 or 7.0.3iFix021. Instructions for downloading these fixes are available on the IBM Support Fix Central website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.