MEDIUM · 5.0

CVE-2014-8926

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 ...

Vulnerability Description

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmEndpoint Manager Family9.0
IbmLicense Metric Tool7.2.2
IbmTivoli Asset Discovery For Distributed7.2.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8926?

CVE-2014-8926 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 ...

How severe is CVE-2014-8926?

CVE-2014-8926 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8926?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Endpoint Manager Family, Ibm License Metric Tool, Ibm Tivoli Asset Discovery For Distributed.