The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-0350 The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-05T22:15:23.269Z

Reserved: 2015-12-08T00:00:00

Link: CVE-2016-0315

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-07-08T01:59:07.273

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-0315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.