CVE-2026-14979
published 2026-07-17CVE-2026-14979: IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.36%
28.3th percentile
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | engineering_lifecycle_management | — | — |
| ibm | engineering_lifecycle_management | 7.0.3 ( Interim Fix 001 – ) Interim Fix 021 | — |
| ibm | engineering_lifecycle_management | 7.1.0 ( Interim Fix 001 – ) Interim Fix 009 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remot
ghsa_unreviewed·2026-07-17
CVE-2026-14979 [MEDIUM] CWE-776 IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remot
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
VulDB
IBM Engineering Lifecycle Management up to 7.2.0 XML xml external entity reference (EUVD-2026-45300)
vuldb·2026-07-17·CVSS 5.3
CVE-2026-14979 [MEDIUM] IBM Engineering Lifecycle Management up to 7.2.0 XML xml external entity reference (EUVD-2026-45300)
A vulnerability labeled as critical has been found in IBM Engineering Lifecycle Management up to 7.2.0. Impacted is an unknown function of the component XML Handler. The manipulation results in xml external entity reference.
This vulnerability is identified as CVE-2026-14979. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published