IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21991153 | patch vendor advisory |
http://www.securityfocus.com/bid/94857 | third party advisory vdb entry |