All 6 CVE vulnerabilities found in Engineering Lifecycle Management, with AI-generated Chinese analysis, references, and POCs.
Vendor: IBM
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-14979 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack CWE-776 | 5.3 | Medium | 2026-07-17 |
| CVE-2026-3660 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass CWE-863 | 9.8 | Critical | 2026-05-26 |
| CVE-2026-3603 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack CWE-611 | 7.1 | High | 2026-05-26 |
| CVE-2026-4051 | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution CWE-749 | 7.2 | High | 2026-05-26 |
| CVE-2025-36157 | IBM Engineering Lifecycle Management incorrect authorization CWE-863 | 9.8 | Critical | 2025-08-24 |
| CVE-2022-34355 | IBM Jazz Foundation information disclosure CWE-200 | 4.0 | Medium | 2023-10-06 |
All 6 known CVE vulnerabilities affecting Engineering Lifecycle Management with full Chinese analysis, references, and POCs where available.