CVE-2016-0315: IBM Jazz Reporting Service

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.

Affected products

  • IBM Jazz Reporting Service: version 5.0 only; version 5.0.1 only; version 5.0.2 only; version 6.0 only; version 6.0.1 only

Published 2016-07-08. Last modified 2026-06-17.