IBM Jazz Reporting Service(JRS)是美国IBM公司的一套用于发现跨项目报表的应用程序。该程序可与IBMRationalCLM的Rational解决方案(用于管理开发项目的所有生命周期)集成使用,CLM用户可在仪表板中访问JRS提供的报表,包括显示所有项目的状态,并跨应用程序、跨项目(甚至跨时间表)来汇聚数据。 IBM JRS(Report Builder)中存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。以下版本受到影响:IB
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Jazz Reporting Service | 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-1961 | IBM Emptoris Contract Management 信息泄露漏洞 | |
| CVE-2018-2007 | IBM API Connect 加密问题漏洞 | |
| CVE-2019-4047 | IBM Jazz Reporting Service 信息泄露漏洞 |
No comments yet