HIGH🇵🇱 Wersja polska

CVE-2026-3603

CVSS 7.1v3.1pub. 2026-05-26upd. 2026-07-24

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
  • IBM Engineering Lifecycle Management

    APP
    Ibm
    7.0.37.1.07.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
References

Related vulnerabilities

CVE-2026-3660CRITICAL9.8PL ✓same product

IBM Engineering Lifecycle Management — nieautoryzowany zapis plików konfiguracyjnych serwera

CVE-2026-4051HIGH7.2same product

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privi...

CVE-2020-4495HIGH8.8same product

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions...

CVE-2020-4965HIGH7.5same product

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker t...

CVE-2021-20502HIGH7.1same product

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing X...