First published: Mon May 25 2015(Updated: )
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Endpoint Manager | =9.0 | |
IBM License Metric Tool | =7.2.2 | |
IBM License Metric Tool | =7.5 | |
IBM License Metric Tool | =9.0 | |
IBM Tivoli Asset Discovery for Distributed | =7.2.2.0 | |
IBM Tivoli Asset Discovery for Distributed | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8927 is classified as a high severity vulnerability due to its potential to cause denial of service.
To remediate CVE-2014-8927, upgrade to versions 2.7.0.2050 or later of the affected IBM software components.
CVE-2014-8927 affects IBM License Metric Tool versions 7.2.2, 7.5, and 9; and Tivoli Asset Discovery for Distributed versions 7.2.2 and 7.5.
Yes, CVE-2014-8927 can be exploited remotely, allowing attackers to cause CPU consumption or application crashes.
Exploitation of CVE-2014-8927 can lead to denial of service, resulting in degraded performance or system crashes.