Junglewise Threat Intelligence

CVE-2026-14979: IBM Engineering Lifecycle Management XML entity expansion denial of service

CVE-2026-14979 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Technologies: IBM Engineering Lifecycle Management - Jazz Foundation. Vendors: IBM.

Executive brief

IBM Engineering Lifecycle Management, a suite used by organizations to manage complex product development and software engineering lifecycles, is vulnerable to a denial-of-service attack. An attacker can exploit this flaw to crash the system or make it unresponsive, potentially halting engineering workflows and delaying project timelines. This issue affects the Jazz Foundation component and the DOORS requirements management tool.

Technical details

A vulnerability exists in the Jazz Foundation component of IBM Engineering Lifecycle Management (including DOORS) due to improper restriction of recursive entity references in DTDs (CWE-776). A remote, unauthenticated attacker can exploit this by sending a specially crafted XML document containing malicious entity expansions (often referred to as an XML bomb). When processed, this causes excessive resource consumption (CPU/memory), leading to a denial-of-service condition. The vulnerability is reachable over the network without user interaction. IBM has released interim fixes (iFixes) for versions 7.0.3, 7.1.0, and 7.2.0 to remediate this issue.

Affected products

  • IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3 (iFix001 through iFix021), 7.1.0 (iFix001 through iFix009), 7.2.0, 7.2.0 iFix001

Timeline

  • 2026-07-14: advisory: Initial publication by IBM
  • 2026-07-17: disclosed: NVD publication date

References

Related threats