CVEID: CVE-2018-2004 Description: IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credential disclosure within a trusted session. Affected Products and Versions: Jazz Reporting Service 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.0.6. Remediation/Fixes: - For versions 6.0, 6.0.1, 6.0.2: Download the interim fix from the . - For versions 6.0.3, 6.0.4, 6.0.5, 6.0.6: Download the interim fix from the . CVSS Base Score: 5.4 CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) Document Number: 882260 Modified Date: 23 April 2019