IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21990317 | Vendor Advisory |
http://www.securityfocus.com/bid/93176 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-11-24 19:59
Updated : 2016-11-28 12:05
NVD link : CVE-2016-3028
Mitre link : CVE-2016-3028
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
ibm
- security_access_manager
- security_access_manager_for_web