CVE-2014-8927

CWE-3993 documents3 sources
Severity
5.0MEDIUM
EPSS
0.6%
top 31.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 17

Description

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDibm/license_metric_tool7.2.2, 7.5, 9.0+2
NVDibm/tivoli_asset_discovery7.2.2.0, 7.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2p99-xhhp-cvww: Common Inventory Technology (CIT) before 22022-05-17
CVEList
CVE-2014-8927: Common Inventory Technology (CIT) before 22015-05-25
CVE-2014-8927 (MEDIUM CVSS 5) | Common Inventory Technology (CIT) b | cvebase.io