Information Disclosure Vulnerability in IBM Jazz Reporting Service
CVE-2017-1370
4.9MEDIUM
What is CVE-2017-1370?
The IBM Jazz Reporting Service, specifically in versions 5.0 and 6.0, is susceptible to an information disclosure vulnerability. An attacker could exploit this flaw via the Report Builder administrator configuration page, potentially revealing sensitive information, including user credentials, through error messages. This exposure poses significant security risks, allowing malicious actors to gain unauthorized access to confidential data.
Affected Version(s)
Jazz Reporting Service 5.0
Jazz Reporting Service 5.0.1
Jazz Reporting Service 5.0.2