Page 2 of 7 results (0.004 seconds)

CVSS: 5.0EPSS: 0%CPEs: 6EXPL: 0

Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927. Common Inventory Technology (CIT) anterior a 2.7.0.2050 en IBM License Metric Tool 7.2.2, 7.5, y 9; Endpoint Manger for Software Use Analysis 9; y Tivoli Asset Discovery for Distributed 7.2.2 y 7.5 permite a atacantes remotos causar una denegación de servicio (consumo de CPU o caída de aplicación) a través de una consulta XML manipulada, una vulnerabilidad diferente a CVE-2014-8927. • http://www-01.ibm.com/support/docview.wss?uid=swg21882695 • CWE-399: Resource Management Errors •

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 0

IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. IBM License Metric Tool 9 anterior a 9.1.0.2 no tiene un atributar de apagar el autocompletado para los campos de autenticación, lo que facilita a atacantes remotos obtener el acceso mediante el aprovechamiento de una estación de trabajo desatendida. • http://www-01.ibm.com/support/docview.wss?uid=swg21713641 http://www.securityfocus.com/bid/74437 http://www.securitytracker.com/id/1032256 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •