CVE-2014-8926

IBM License Metric Tool <7.2.2, 7.5, 9 - DoS

Title source: llm
STIX 2.1

Description

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21882695

Scores

EPSS 0.0126
EPSS Percentile 66.4%

Details

CWE
CWE-399
Status published
Products (6)
ibm/endpoint_manager_family 9.0
ibm/license_metric_tool 7.2.2
ibm/license_metric_tool 7.5
ibm/license_metric_tool 9.0.1
ibm/tivoli_asset_discovery_for_distributed 7.2.2.0
ibm/tivoli_asset_discovery_for_distributed 7.5
Published May 25, 2015
Tracked Since Feb 18, 2026