CVE-2016-0318 Information
Feb 14, 2021
cve
Description
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action which allows remote attackers to obtain access by leveraging an unattended workstation.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Reference
http://www.securityfocus.com/bid/92466 http://www-01.ibm.com/support/docview.wss?uid=swg21983137
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.0
Share on: