Executive brief
IBM Engineering Lifecycle Management, a suite used by organizations to manage complex software and systems development, contains a critical security flaw. An unauthenticated attacker can remotely modify server configuration files, which allows them to bypass security controls and gain full unauthorized access to the application. This could lead to the theft of intellectual property, disruption of development workflows, or total compromise of the management platform.
Technical details
An authentication bypass vulnerability exists in the Jazz Foundation component of IBM Engineering Lifecycle Management due to incorrect authorization (CWE-863). The flaw allows a remote, unauthenticated attacker to modify server property files. By manipulating these configuration files, an attacker can escalate privileges or bypass authentication mechanisms entirely to gain unauthorized access to the application. The vulnerability is exploitable over the network with low complexity and requires no user interaction. IBM has released interim fixes (iFixes) to address this issue across versions 7.0.3, 7.1.0, and 7.2.0.
Affected products
- IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3 through iFix021, 7.1.0 through iFix009, 7.2.0 through iFix001
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Interim fixes released for affected versions.