Vulnerability Description
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Jazz Reporting Service | 5.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21983147Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21983147Vendor Advisory
FAQ
What is CVE-2016-0315?
CVE-2016-0315 is a vulnerability with a CVSS score of 8.8 (HIGH). The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, whi...
How severe is CVE-2016-0315?
CVE-2016-0315 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0315?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Jazz Reporting Service.