Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.
| Software | From | Fixed in |
|---|---|---|
| ibm / tivoli_asset_discovery_for_distributed | 7.2.2.0 | 7.2.2.0.x |
| ibm / license_metric_tool | 7.5 | 7.5.x |
| ibm / license_metric_tool | 7.2.2 | 7.2.2.x |
| ibm / tivoli_asset_discovery_for_distributed | 7.5 | 7.5.x |
| ibm / license_metric_tool | 9.0.1 | 9.0.1.x |
| ibm / endpoint_manager_family | 9.0 | 9.0.x |