IBM Security Bulletin: Multiple security vulnerabilities affect the Report Builder that is shipped with Jazz Reporting Service

There are multiple security vulnerabilities in the Report Builder shipped with Jazz Reporting Service.

CVE(s): CVE-2017-1157, CVE-2016-9986, CVE-2016-9987, CVE-2016-9988, CVE-2016-9989, CVE-2017-1096

Affected product(s) and affected version(s):

Jazz Reporting Service 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, and 6.0.3.

CVE-2017-1096 affects only the 6.0.3 release.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2ssLEPH
X-Force Database: http://ift.tt/2tbPAS1
X-Force Database: http://ift.tt/2ssvAxu
X-Force Database: http://ift.tt/2tc4hVg
X-Force Database: http://ift.tt/2ssvzcU
X-Force Database: http://ift.tt/2tckiL2
X-Force Database: http://ift.tt/2srY7n3

The post IBM Security Bulletin: Multiple security vulnerabilities affect the Report Builder that is shipped with Jazz Reporting Service appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2tca1yx