CVE-2026-3603: IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix022 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.1.0Patch iFix010 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.2.0Patch iFix002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3603?
CVE-2026-3603 has a high severity score of 7.1.
How do I fix CVE-2026-3603?
To fix CVE-2026-3603, it is recommended to upgrade to the latest interim fix, which is iFix022 for affected versions.
What type of attack is associated with CVE-2026-3603?
CVE-2026-3603 is associated with an XML external entity injection (XXE) attack.
Which versions of IBM Engineering Lifecycle Management are affected by CVE-2026-3603?
Affected versions include IBM Engineering Lifecycle Management 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001.
Who can exploit CVE-2026-3603?
An authenticated attacker can exploit CVE-2026-3603 when processing XML data within the vulnerable versions.