XML External Entity Vulnerability in IBM License Metric Tool and Tivoli Asset Discovery
CVE-2014-8924
Currently unrated
Summary
The vulnerability in IBM License Metric Tool and Tivoli Asset Discovery arises from improper handling of XML input. Attackers can exploit this weakness to craft XML data that includes an external entity declaration, enabling them to read sensitive files from the server or send TCP requests to other intranet servers. This exposure poses significant risk as it allows unauthorized access to internal resources, making it crucial for users to apply the latest patches or updates to mitigate potential threats.
References
Timeline
Vulnerability published
Vulnerability Reserved