Vulnerability Description
Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Endpoint Manager Family | 9.0 |
| Ibm | License Metric Tool | 7.2.2 |
| Ibm | Tivoli Asset Discovery For Distributed | 7.2.2.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21882695PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21882695PatchVendor Advisory
FAQ
What is CVE-2014-8926?
CVE-2014-8926 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 ...
How severe is CVE-2014-8926?
CVE-2014-8926 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8926?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Endpoint Manager Family, Ibm License Metric Tool, Ibm Tivoli Asset Discovery For Distributed.