CVE-2016-0325

medium
Published 2016-11-24 · Modified 2026-05-06
CVSS v3
6.3
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2
7.5
VIR risk
6.3

Description

IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to execute arbitrary OS commands via a crafted request.

Predictions

Exploit likelihood
73%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21991478

Application impact

VendorProductVersionsFixed
ibm ibmrational_team_concert3.0.1.6
ibm ibmrational_team_concert4.0.0
ibm ibmrational_team_concert4.0.1
ibm ibmrational_team_concert4.0.2
ibm ibmrational_team_concert4.0.3
ibm ibmrational_team_concert4.0.4
ibm ibmrational_team_concert4.0.5
ibm ibmrational_team_concert4.0.6
ibm ibmrational_team_concert4.0.7
ibm ibmrational_team_concert5.0.0
ibm ibmrational_team_concert5.0.1
ibm ibmrational_team_concert5.0.2
ibm ibmrational_team_concert6.0.0
ibm ibmrational_team_concert6.0.1
ibm ibmrational_team_concert6.0.2

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.