A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-5402