A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-6347 A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T01:00:59.994Z

Reserved: 2016-06-10T00:00:00

Link: CVE-2016-5402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-31T13:29:00.443

Modified: 2024-11-21T02:54:14.663

Link: CVE-2016-5402

cve-icon Redhat

Severity : Important

Publid Date: 2016-11-30T00:00:00Z

Links: CVE-2016-5402 - Bugzilla

cve-icon OpenCVE Enrichment

No data.