Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling. | |
| Analizada | Baja (3.5) | 0.22% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources. | |
| Analizada | Alta (7.2) | 0.38% | — | IBM Jazz Reporting Service | 2/4/2025 | 17/6/2026 | IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system. | |
| Modificada | Media (4.4) | 0.16% | — | IBM Jazz Reporting Service | 13/6/2024 | 17/6/2026 | IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363. | |
| Modificada | Media (5.4) | 0.52% | — | IBM Jazz Reporting Service | 13/5/2021 | 17/6/2026 | IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Jazz Reporting Service | 18/2/2021 | 17/6/2026 | IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Jazz Reporting Service | 19/11/2020 | 17/6/2026 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (6.1) | 0.73% | — | IBM Jazz Reporting Service | 10/8/2020 | 17/6/2026 | IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Jazz Reporting Service | 10/8/2020 | 17/6/2026 | IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.1) | 0.73% | — | IBM Jazz Reporting Service | 10/8/2020 | 17/6/2026 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Jazz Reporting Service | 28/5/2020 | 17/6/2026 | IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071. | |
| Modificada | Crítica (9.8) | 1.4% | — | IBM Jazz Reporting Service | 9/1/2020 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962. | |
| Modificada | Media (5.4) | 0.68% | — | IBM Jazz Reporting Service | 1/10/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Media (5.4) | 0.68% | — | IBM Jazz Reporting Service | 1/10/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Media (5.4) | 0.68% | — | IBM Jazz Reporting Service | 1/10/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Media (5.4) | 0.94% | — | IBM Jazz Reporting Service | 29/5/2019 | 17/6/2026 | IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158974. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Jazz Reporting Service | 29/4/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243. | |
| Modificada | Media (5.4) | 0.94% | — | IBM Jazz Reporting Service | 29/4/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006. | |
| Modificada | Media (5.4) | 0.97% | — | IBM Jazz Reporting Service | 8/1/2019 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0.3, 6.0.4, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152785. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Jazz Reporting Service | 16/11/2018 | 17/6/2026 | The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579. | |
| Modificada | Media (5.4) | 0.93% | — | IBM Jazz Reporting Service | 25/4/2018 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.93% | — | IBM Jazz Reporting Service | 25/4/2018 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5) | 0.95% | — | IBM Jazz Reporting Service | 1/11/2017 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455. | |
| Modificada | Media (5.3) | 0.95% | — | IBM Jazz Reporting Service | 14/9/2017 | 17/6/2026 | An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information. |