CVE-2016-0325: OS Command Injection
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to execute arbitrary OS commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0325?
CVE-2016-0325 has a moderate severity level, indicating potential risks to IBM Rational software components.
How do I fix CVE-2016-0325?
To resolve CVE-2016-0325, upgrade IBM Rational Collaborative Lifecycle Management and its related products to the latest iFix version indicated in the vulnerability report.
Which versions are affected by CVE-2016-0325?
CVE-2016-0325 affects several versions of IBM Rational Collaborative Lifecycle Management, Rational Quality Manager, and Rational Team Concert prior to specified iFix releases.
What products are vulnerable to CVE-2016-0325?
IBM Rational Collaborate Lifecycle Management, Rational Quality Manager, and Rational Team Concert are among the products vulnerable to CVE-2016-0325.
Is there a workaround for CVE-2016-0325?
No specific workarounds are provided for CVE-2016-0325; updating the software is the recommended action.