CVE-2014-8926

CWE-3993 documents3 sources
Severity
5.0MEDIUM
EPSS
0.6%
top 31.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 17

Description

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDibm/license_metric_tool7.2.2, 7.5, 9.0.1+2
NVDibm/tivoli_asset_discovery7.2.2.0, 7.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c5gr-p444-69m5: Common Inventory Technology (CIT) before 22022-05-17
CVEList
CVE-2014-8926: Common Inventory Technology (CIT) before 22015-05-25