PT-2016-4149 · Ibm · Ibm Rational Quality Manager+1
Published
2016-10-22
·
Updated
2016-11-28
·
CVE-2016-0326
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 3.0.1.6 before iFix8
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 4.x before 4.0.7 iFix11
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 5.x before 5.0.2 iFix17
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management versions 6.x before 6.0.1 iFix3
Description
The issue allows remote authenticated users to execute arbitrary OS commands via a crafted HTML request.
Recommendations
For versions 3.0.1.6, apply iFix8 to resolve the issue.
For versions 4.x, apply iFix11 to version 4.0.7 to resolve the issue.
For versions 5.x, apply iFix17 to version 5.0.2 to resolve the issue.
For versions 6.x, apply iFix3 to version 6.0.1 to resolve the issue.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Rational Quality Manager
Ibm Rational Collaborative Lifecycle Management