CVE-2016-0326: IBM Rational Collaborative Lifecycle Management

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."

Affected products

  • IBM Rational Collaborative Lifecycle Management: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
  • IBM Rational Quality Manager: version 3.0.1.6 only; version 4.0 only; version 4.0.0.1 only; version 4.0.0.2 only; version 4.0.1 only; version 4.0.2 only; …

Published 2016-10-22. Last modified 2026-06-17.