Junglewise Threat Intelligence

CVE-2026-3603: IBM Engineering Lifecycle Management XXE in Jazz Foundation

CVE-2026-3603 · Severity: high · CVSS 7.1 · Published 2026-05-26

Technologies: IBM Engineering Lifecycle Management - Jazz Foundation. Vendors: IBM.

Executive brief

IBM Engineering Lifecycle Management, a suite of tools used by organizations to manage the software development process, is vulnerable to a security flaw in how it handles XML data. An authorized user could exploit this weakness to view sensitive internal information or cause system performance issues by consuming excessive memory. This could lead to unauthorized data disclosure or disruptions in the development environment.

Technical details

An XML External Entity (XXE) injection vulnerability exists in the Jazz Foundation component of IBM Engineering Lifecycle Management. The issue stems from improper restriction of XML external entity references (CWE-611) when the application processes XML data. A remote attacker with low-level authentication can exploit this by sending a specially crafted XML payload to the server. Successful exploitation allows the attacker to read local files, access internal network resources, or trigger a denial-of-service condition via memory exhaustion. IBM has released patches (iFixes) for versions 7.0.3, 7.1.0, and 7.2.0 to address this vulnerability.

Affected products

  • IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3 iFix001 - iFix021, 7.1.0 iFix001 - iFix009, 7.2.0, 7.2.0 iFix001

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched

References

Related threats