IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21990317 | Vendor Advisory |
http://www.securityfocus.com/bid/93176 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2016-11-25 03:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-3028
Mitre link : CVE-2016-3028
CVE.ORG link : CVE-2016-3028
JSON object : View
Products Affected
ibm
- security_access_manager_for_web
- security_access_manager
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')