Description
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information.
Affected products
- IBM Corporation / Jazz Reporting Service6 – 6
- IBM Corporation / Jazz Reporting Service5.0 – 5.0
- IBM Corporation / Jazz Reporting Service5.0.1 – 5.0.1
- IBM Corporation / Jazz Reporting Service5.0.2 – 5.0.2
- IBM Corporation / Jazz Reporting Service6.0 – 6.0
- IBM Corporation / Jazz Reporting Service6.0.1 – 6.0.1
- IBM Corporation / Jazz Reporting Service6.0.2 – 6.0.2