CVE-2026-3660: IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix022 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.1.0Patch iFix010 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.2.0Patch iFix002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3660?
CVE-2026-3660 has a critical severity rating of 9.8.
What are the potential impacts of CVE-2026-3660?
CVE-2026-3660 allows an unauthenticated remote attacker to update server property files, potentially leading to unauthorized access to the application.
How do I fix CVE-2026-3660?
To fix CVE-2026-3660, upgrade to the appropriate iFix for your version of IBM Engineering Lifecycle Management.
Which versions of IBM Engineering Lifecycle Management are affected by CVE-2026-3660?
CVE-2026-3660 affects IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0.
Is CVE-2026-3660 exploitable remotely?
Yes, CVE-2026-3660 is exploitable remotely by attackers without authentication.