Vulnerability Details CVE-2016-0318
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.5%
CVSS Severity
CVSS v3 Score 5.0
CVSS v2 Score 6.0
Products affected by CVE-2016-0318
-
cpe:2.3:a:ibm:jazz_reporting_service:6.0
-
cpe:2.3:a:ibm:jazz_reporting_service:6.0.1