CVE-2014-8924
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
El servidor en IBM License Metric Tool 7.2.2 anterior a IF15 y 7.5 anterior a IF24 y Tivoli Asset Discovery for Distributed 7.2.2 anterior a IF15 y 7.5 anterior a IF24 permite a atacantes remotos leer ficheros arbitrarios o enviar solicitudes TCP a servidores de intranet a través de datos XML que contiene una declaración de entidad externa en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-14 CVE Reserved
- 2015-05-20 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1032275 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21882820 | 2017-01-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | License Metric Tool Search vendor "Ibm" for product "License Metric Tool" | 7.2.2 Search vendor "Ibm" for product "License Metric Tool" and version "7.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | License Metric Tool Search vendor "Ibm" for product "License Metric Tool" | 7.5 Search vendor "Ibm" for product "License Metric Tool" and version "7.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Asset Discovery For Distributed Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" | 7.2.2 Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" and version "7.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Asset Discovery For Distributed Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" | 7.5 Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" and version "7.5" | - |
Affected
|