Description
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the XML processing of IBM Engineering Lifecycle Management – Jazz Foundation permits unrestricted XML entity expansion, allowing a remote attacker to consume excessive CPU or memory and crash or hang the affected service. The weakness falls under CWE‑776. An attacker could send a crafted XML document that triggers the expansion, overloading the application and causing it to become unavailable to legitimate users, potentially disrupting project tracking and collaboration activities.

Affected Systems

IBM Engineering Lifecycle Management – Jazz Foundation versions 7.0.3, 7.1.0, and 7.2.0, including the interim fixes released up to, but not including, the specified iFixes. The vendor recommends upgrading to iFix022 for 7.0.3, iFix010 for 7.1.0, and iFix002 for 7.2.0 to resolve the XML entity expansion vulnerability.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low probability of automated exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further implying limited known exploitation. Attackers would need network reachability to a Jazz Foundation endpoint that processes XML; with such access, a single malicious XML payload could lead to service denial.

Generated by OpenCVE AI on July 30, 2026 at 23:36 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below: Affected Product(s)Version(s)Remediation/Fix/Instructions IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3Download and install  iFix022 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Engineering Lifecycle Management - Jazz Foundation 7.1.0Download and install  iFix010 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Engineering Lifecycle Management - Jazz Foundation 7.2.0Download and install  iFix002 https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Apply iFix022 from IBM support to Jazz Foundation 7.0.3 to address XML entity processing issues.
  • Apply iFix010 from IBM support to Jazz Foundation 7.1.0 to remediate the XML entity expansion flaw.
  • Apply iFix002 from IBM support to Jazz Foundation 7.2.0 to prevent denial of service via XML entities.
  • Configure the Java XML parser used by Jazz Foundation to disable DTD processing or to limit the size of entity expansion, ensuring malformed XML cannot exhaust resources.
  • Restrict network access to the XML service endpoints to trusted hosts or implement firewall rules to block anomalous XML traffic.

Generated by OpenCVE AI on July 30, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3:interim_fix_021:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0:interim_fix_009:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0and7.2.0:interim_fix_001:*:*:*:*:*:*

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Title IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
First Time appeared Ibm
Ibm engineering Lifecycle Management
Weaknesses CWE-776
CPEs cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3:interim_fix_021:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Lifecycle Management
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Engineering Lifecycle Management
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-28T20:25:25.340Z

Reserved: 2026-07-07T16:58:17.358Z

Link: CVE-2026-14979

cve-icon Vulnrichment

Updated: 2026-07-20T15:16:50.730Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-776

    Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')