PT-2016-4149 · Ibm · Ibm Rational Quality Manager+1

Published

2016-10-22

·

Updated

2016-11-28

·

CVE-2016-0326

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 3.0.1.6 before iFix8 IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 4.x before 4.0.7 iFix11 IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 5.x before 5.0.2 iFix17 IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 6.x before 6.0.1 iFix3
Description The issue allows remote authenticated users to execute arbitrary OS commands via a crafted HTML request.
Recommendations For versions 3.0.1.6, apply iFix8 to resolve the issue. For versions 4.x, apply iFix11 to version 4.0.7 to resolve the issue. For versions 5.x, apply iFix17 to version 5.0.2 to resolve the issue. For versions 6.x, apply iFix3 to version 6.0.1 to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0326

Affected Products

Ibm Rational Quality Manager
Ibm Rational Collaborative Lifecycle Management