### [CVE-2016-5402](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5402) ![](https://img.shields.io/static/v1?label=Product&message=cfme&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%20n%2Fa%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-94&color=brighgreen) ### Description A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as. ### POC #### Reference No PoCs from references. #### Github - https://github.com/auditt7708/rhsecapi