CVE-2016-0326: Command Injection
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0326?
CVE-2016-0326 is considered a high-severity vulnerability allowing remote authenticated users to execute arbitrary OS commands.
How do I fix CVE-2016-0326?
To remediate CVE-2016-0326, upgrade to IBM Rational Quality Manager or Rational Collaborative Lifecycle Management versions that are patched for this vulnerability.
Which versions are affected by CVE-2016-0326?
CVE-2016-0326 affects multiple versions including IBM Rational Collaborative Lifecycle Management 4.x, 5.x, 6.x, and IBM Rational Quality Manager up to 6.0.1.
Can CVE-2016-0326 be exploited without authentication?
No, CVE-2016-0326 requires that the attacker is a remote authenticated user to exploit the vulnerability.
What are the implications of CVE-2016-0326 for network security?
CVE-2016-0326 poses critical risks as it allows authenticated users to execute OS commands, potentially compromising the entire system.