CVE-2014-8924
Status: ModifiedMedium (6.4)—
The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
- Base score: 6.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.78%
- Percentile among all scored CVEs: 77
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2014-8924",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-05-20T10:59:01.353",
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21882820",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securitytracker.com/id/1032275",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21882820",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1032275",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
},
{
"lang": "es",
"value": "El servidor en IBM License Metric Tool 7.2.2 anterior a IF15 y 7.5 anterior a IF24 y Tivoli Asset Discovery for Distributed 7.2.2 anterior a IF15 y 7.5 anterior a IF24 permite a atacantes remotos leer ficheros arbitrarios o enviar solicitudes TCP a servidores de intranet a través de datos XML que contiene una declaración de entidad externa en conjunto con una referencia de entidad, relacionado con un problema de entidad externa XML (XXE)."
}
],
"lastModified": "2026-06-17T00:17:32.420",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:license_metric_tool:7.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26CC2FED-B9A4-48E5-AFB2-084212D667A5"
},
{
"criteria": "cpe:2.3:a:ibm:license_metric_tool:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BE43D33-3FF7-4144-B220-5F3CCFE5E458"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_asset_discovery_for_distributed:7.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70785B4F-6CE9-40AC-93C5-9FF3B8C72B1F"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_asset_discovery_for_distributed:7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9545AA8-2F1E-4FB9-9D22-B3E109047F9B"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/611.html\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>",
"sourceIdentifier": "psirt@us.ibm.com"
}