Vulnerability Bulletins

IBM Security Bulletin: External Entity Injection vulnerability in IBM License Metric Tool v7.5 & v7.2.2 and IBM Tivoli Asset Discovery for Distributed v7.5 & v7.2.2 - CVE-2014-8924

   
Affected software IBM
 
IBM License Metric Tool v7.5 & v7.2.2 and IBM Tivoli Asset Discovery for Distributed v7.5 & v7.2.2 servers are vulnerable to External Entity Injection attack. Sending specially crafted request to server allows for file extraction from servers machine or environment, or extraction of information pertaining to the servers machine or its networking setup. CVE(s): CVE-2014-8924 Affected product(s) and affected version(s): IBM License Metric Tool v7.5, v7.2.2 IBM Tivoli Asset

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_external_entity_injection_vulnerability_in_ibm_license_metric_tool_v7_5_v7_2_2_and_ibm_tivoli_asset_discovery_for_distributed_v7_5_v7_2_2_cve_2014_8924?lang=en_us