Impact
A flaw in the XML processing of IBM Engineering Lifecycle Management – Jazz Foundation permits unrestricted XML entity expansion, allowing a remote attacker to consume excessive CPU or memory and crash or hang the affected service. The weakness falls under CWE‑776. An attacker could send a crafted XML document that triggers the expansion, overloading the application and causing it to become unavailable to legitimate users, potentially disrupting project tracking and collaboration activities.
Affected Systems
IBM Engineering Lifecycle Management – Jazz Foundation versions 7.0.3, 7.1.0, and 7.2.0, including the interim fixes released up to, but not including, the specified iFixes. The vendor recommends upgrading to iFix022 for 7.0.3, iFix010 for 7.1.0, and iFix002 for 7.2.0 to resolve the XML entity expansion vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low probability of automated exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further implying limited known exploitation. Attackers would need network reachability to a Jazz Foundation endpoint that processes XML; with such access, a single malicious XML payload could lead to service denial.
OpenCVE Enrichment