CVE-2014-8927
Summary
| CVE | CVE-2014-8927 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-25 14:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Endpoint Manager Family | 9.0 | All | All | All |
| Application | Ibm | License Metric Tool | 7.2.2 | All | All | All |
| Application | Ibm | License Metric Tool | 7.5 | All | All | All |
| Application | Ibm | License Metric Tool | 9.0 | All | All | All |
| Application | Ibm | Tivoli Asset Discovery For Distributed | 7.2.2.0 | All | All | All |
| Application | Ibm | Tivoli Asset Discovery For Distributed | 7.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: wscanhw and wscansw vulnerabilities in scanner component of IBM License Metric Tool v9, v7.5, 7.2.2, IBM Endpoint Manger for Software Use Analysis v9 and IBM Tivoli Asset Discovery for Distributed v7.5, v7.2.2 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.