4
CVSSv2

CVE-2015-7466

Published: 10/01/2016 Updated: 12/01/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 3.1 | Impact Score: 1.4 | Exploitability Score: 1.6
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 prior to 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm jazz reporting service 6.0