IBM Security Bulletin: IBM Security Access Manager for Web is affected by a command injection vulnerability (CVE-2015-5018)

IBM Security Access Manager for Web allows attackers to run arbitrary commands on the Operating System of the appliance. An attacker with access to the LMI could use a command injection attack to gain elevated access to the appliance. ...

from IBM Product Security Incident Response Team http://ift.tt/1Ra7Y5I