Metrics
Affected Vendors & Products
No advisories yet.
Solution
IBM recommends customers on ELM 7.0.1, 7.0.2 or any version below 7.0.3 to upgrade your products to Maintenance release 7.0.3 and apply below fix. Optionally, upgrade to the latest 7.2.0 version. Affected Product(s)Version(s)Remediation/Fix/InstructionsIBM Engineering Lifecycle Management - Jazz Foundation 7.0.3Download and install iFix020 https://www.ibm.com/support/fixcentral/swg/downloadFixes or laterIBM Engineering Lifecycle Management - Jazz Foundation 7.1.0Download and install iFix006 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7258304 |
|
Mon, 02 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability. | |
| Title | IBM Jazz Foundation access control violation | |
| First Time appeared |
Ibm
Ibm jazz Foundation |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ibm:jazz_foundation:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.0.3:ifix019:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.1.0:ifix005:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm jazz Foundation |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-02-02T16:45:31.338Z
Reserved: 2025-12-31T14:28:58.770Z
Link: CVE-2025-15395
Updated: 2026-02-02T16:45:23.182Z
Status : Received
Published: 2026-02-02T16:16:18.187
Modified: 2026-02-02T16:16:18.187
Link: CVE-2025-15395
No data.
OpenCVE Enrichment
No data.