// For flags

CVE-2014-8924

 

Severity Score

6.4
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

El servidor en IBM License Metric Tool 7.2.2 anterior a IF15 y 7.5 anterior a IF24 y Tivoli Asset Discovery for Distributed 7.2.2 anterior a IF15 y 7.5 anterior a IF24 permite a atacantes remotos leer ficheros arbitrarios o enviar solicitudes TCP a servidores de intranet a través de datos XML que contiene una declaración de entidad externa en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-11-14 CVE Reserved
  • 2015-05-20 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
License Metric Tool
Search vendor "Ibm" for product "License Metric Tool"
7.2.2
Search vendor "Ibm" for product "License Metric Tool" and version "7.2.2"
-
Affected
Ibm
Search vendor "Ibm"
License Metric Tool
Search vendor "Ibm" for product "License Metric Tool"
7.5
Search vendor "Ibm" for product "License Metric Tool" and version "7.5"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Asset Discovery For Distributed
Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed"
7.2.2
Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" and version "7.2.2"
-
Affected
Ibm
Search vendor "Ibm"
Tivoli Asset Discovery For Distributed
Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed"
7.5
Search vendor "Ibm" for product "Tivoli Asset Discovery For Distributed" and version "7.5"
-
Affected