CVE-2016-0396: Command Injection
Published Feb 1, 2017
·Updated
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
Affected Software
4 affected components
IBM BigFix Platform=9.0
IBM BigFix Platform=9.1
IBM BigFix Platform=9.2
IBM BigFix Platform=9.5
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0396?
CVE-2016-0396 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0396?
To fix CVE-2016-0396, you should upgrade to a non-vulnerable version of IBM Tivoli Endpoint Manager or apply the relevant security patches provided by IBM.
3
What versions of IBM BigFix Platform are affected by CVE-2016-0396?
CVE-2016-0396 affects IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5.
4
What type of vulnerability is CVE-2016-0396?
CVE-2016-0396 is a command injection vulnerability that allows users to execute commands with higher privileges under specific circumstances.
5
Can CVE-2016-0396 be exploited remotely?
Yes, CVE-2016-0396 can potentially be exploited remotely by an attacker if certain conditions are met.