IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257 - Broken Link | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322 - Broken Link | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326 - Broken Link | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21990317 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/93176 - |
Information
Published : 2016-11-25 03:59
Updated : 2024-11-21 02:49
NVD link : CVE-2016-3028
Mitre link : CVE-2016-3028
CVE.ORG link : CVE-2016-3028
JSON object : View
Products Affected
ibm
- security_access_manager_for_web
- security_access_manager
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')