IBM License Metric Tool 9.0

CPE Details

IBM License Metric Tool 9.0
9.0
2015-05-20
13h44 +00:00
2015-05-22
14h59 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:license_metric_tool:9.0:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

license_metric_tool

Version

9.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-43044 2023-09-28 17h23 +00:00 IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 266893.
7.5
Haute
CVE-2016-8964 2017-07-13 15h00 +00:00 IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
9.8
Critique
CVE-2015-4929 2015-10-10 23h00 +00:00 IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manager for Software Use Analysis 9 before 9.2.1.0 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via a REST API request.
4
CVE-2014-4774 2015-05-25 12h00 +00:00 Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.
6.8
CVE-2014-4778 2015-05-25 12h00 +00:00 IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.
4.3
CVE-2014-8927 2015-05-25 12h00 +00:00 Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.
5
CVE-2014-4776 2015-05-20 08h00 +00:00 IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
2.1