CVE-2019-4184 describes a cross-site scripting (XSS) vulnerability affecting IBM Jazz Reporting Service versions 6.0 through 6.0.6.1. An authenticated attacker can inject malicious JavaScript into the Web UI, potentially leading to credential disclosure within a trusted user session. This vulnerability has a CVSS v3.0 score of 5.4 (Medium), indicating a network-based attack with low attack complexity and requiring user interaction. While it could compromise confidentiality and integrity, it does not impact availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The CVE has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, <= 6.0.6.1CPE matchmatch criteria | cpe:2.3:a:ibm:jazz_reporting_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.