First published: Mon May 25 2015(Updated: )
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Endpoint Manager Family | =9.0 | |
IBM License Metric Tool | =7.2.2 | |
IBM License Metric Tool | =7.5 | |
IBM License Metric Tool | =9.0.1 | |
Ibm Tivoli Asset Discovery For Distributed | =7.2.2.0 | |
Ibm Tivoli Asset Discovery For Distributed | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8926 has a moderate severity level due to its potential for denial of service.
To fix CVE-2014-8926, upgrade your software to the latest version that is not affected by this vulnerability.
CVE-2014-8926 affects IBM License Metric Tool versions 7.2.2, 7.5, and 9, as well as Tivoli Asset Discovery for Distributed version 7.2.2 and 7.5.
Yes, CVE-2014-8926 can be exploited remotely by attackers to cause denial of service.
CVE-2014-8926 can lead to increased CPU consumption or application crashes.