CVE-2015-7466

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*

Information

Published : 2016-01-09 19:59

Updated : 2016-01-11 18:43


NVD link : CVE-2015-7466

Mitre link : CVE-2015-7466


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Advertisement

dedicated server usa

Products Affected

ibm

  • jazz_reporting_service