CVE-2016-3028: OS Command Injection
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3028?
CVE-2016-3028 is rated as a high-severity vulnerability due to its potential for remote command execution by authenticated users.
How do I fix CVE-2016-3028?
To fix CVE-2016-3028, upgrade to IBM Security Access Manager version 9.0.1.0 IF5, 8.0.1.4 IF3, or 7.0 IF2.
Who is affected by CVE-2016-3028?
CVE-2016-3028 affects users of IBM Security Access Manager for Web versions 7.0, 8.0, and 9.0 before the specified fixes.
What types of attacks can CVE-2016-3028 enable?
CVE-2016-3028 can enable attackers to execute arbitrary commands, potentially compromising the application and sensitive data.
Is authentication required to exploit CVE-2016-3028?
Yes, CVE-2016-3028 requires that the attacker be an authenticated user to exploit the vulnerability.