IBM Engineering Lifecycle Management是美国国际商业机器(IBM)公司的一个工程生命周期管理平台。 IBM Engineering Lifecycle Management 7.0.3版本、7.1.0版本和7.2.0版本存在安全漏洞,该漏洞源于处理XML数据时容易受到XML外部实体注入攻击,可能导致暴露敏感信息或消耗内存资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Engineering Lifecycle Management | 7.0.3 Interim Fix 001≤ Interim Fix 021 |
affected |
7.1.0 Interim Fix 001≤ Interim Fix 009 |
affected | ||
7.2.0 and 7.2.0 Interim Fix 001 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Engineering Lifecycle Management | 7.0.3 Interim Fix 001 ~ Interim Fix 021 |
cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3660 | 9.8 CRITICAL | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Byp |
| CVE-2026-8633 | 9.8 CRITICAL | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8855 | 8.1 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8834 | 8.0 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8856 | 7.7 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8850 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8854 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8620 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8835 | 7.3 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-4051 | 7.2 HIGH | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth R |
| CVE-2025-36126 | 6.4 MEDIUM | IBM Cognos Analytics is affected by Cross-site scripting. |
| CVE-2026-8852 | 6.2 MEDIUM | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2025-13755 | 5.5 MEDIUM | IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase |
| CVE-2025-36148 | 5.4 MEDIUM | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to c |
| CVE-2025-36145 | 5.4 MEDIUM | Multiple Vulnerabilities in watsonx.data |
| CVE-2025-14290 | 5.4 MEDIUM | IBM webMethods Integration Sever is vulnerable to server-side request forgery |
| CVE-2025-36221 | 5.3 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2025-36220 | 4.3 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-9170 | IBM HTTP Server is affected by multiple vulnerabilities |
No comments yet