CVE-2014-8924

3 documents3 sources
Severity
6.4MEDIUM
EPSS
0.3%
top 48.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 17

Description

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDibm/license_metric_tool7.2.2, 7.5+1
NVDibm/tivoli_asset_discovery7.2.2, 7.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xchp-v76c-8jf6: The server in IBM License Metric Tool 72022-05-17
CVEList
CVE-2014-8924: The server in IBM License Metric Tool 72015-05-20
CVE-2014-8924 (MEDIUM CVSS 6.4) | The server in IBM License Metric To | cvebase.io