MEDIUM · 6.4

CVE-2014-8924

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary f...

Vulnerability Description

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
IbmLicense Metric Tool7.2.2
IbmTivoli Asset Discovery For Distributed7.2.2

References

FAQ

What is CVE-2014-8924?

CVE-2014-8924 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary f...

How severe is CVE-2014-8924?

CVE-2014-8924 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8924?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm License Metric Tool, Ibm Tivoli Asset Discovery For Distributed.