- Description
- Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.
- Source
- psirt@us.ibm.com
- NVD status
- Deferred
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
- nvd@nist.gov
- CWE-399
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:endpoint_manager_family:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B598889D-9542-48AC-BC47-A5AC6003C1E1"
},
{
"criteria": "cpe:2.3:a:ibm:license_metric_tool:7.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26CC2FED-B9A4-48E5-AFB2-084212D667A5"
},
{
"criteria": "cpe:2.3:a:ibm:license_metric_tool:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BE43D33-3FF7-4144-B220-5F3CCFE5E458"
},
{
"criteria": "cpe:2.3:a:ibm:license_metric_tool:9.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40A6C16F-6CA8-4780-B5DE-2A118DA05AFC"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_asset_discovery_for_distributed:7.2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C71EE3DE-6581-4A92-BBB3-EA795439B643"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_asset_discovery_for_distributed:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9545AA8-2F1E-4FB9-9D22-B3E109047F9B"
}
],
"operator": "OR"
}
]
}
]