CVE-2026-14979: IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix022 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.1.0Patch iFix010 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.2.0Patch iFix002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14979?
CVE-2026-14979 has a medium severity rating of 5.3.
What does CVE-2026-14979 affect?
CVE-2026-14979 affects IBM Engineering Lifecycle Management - Jazz Foundation, specifically the DOORS component.
How can I mitigate the risk of CVE-2026-14979?
To mitigate CVE-2026-14979, apply the latest interim fixes for your version of IBM Engineering Lifecycle Management.
What type of attack is associated with CVE-2026-14979?
CVE-2026-14979 is associated with an XML Entity Expansion attack that could lead to a denial of service.
Which versions of IBM Engineering Lifecycle Management are impacted by CVE-2026-14979?
The impacted versions include IBM Engineering Lifecycle Management 7.0.3 through 7.2.0 Interim Fix 001.