No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below: Affected Product(s)Version(s)Remediation/Fix/Instructions IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3Download and install iFix022 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Engineering Lifecycle Management - Jazz Foundation 7.1.0Download and install iFix010 https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Engineering Lifecycle Management - Jazz Foundation 7.2.0Download and install iFix002 https://www.ibm.com/support/fixcentral/swg/downloadFixes
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7274079 |
|
Tue, 26 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0 ( through ) Interim Fix 009, and 7.2.0 ( through ) Interim Fix 001 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application. | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application. |
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0 ( through ) Interim Fix 009, and 7.2.0 ( through ) Interim Fix 001 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application. | |
| Title | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Bypass | |
| First Time appeared |
Ibm
Ibm engineering Lifecycle Management |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3:ifix021:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0:ifix009:*:*:*:*:*:*:* cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0:ifix001:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm engineering Lifecycle Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-05-26T20:12:14.233Z
Reserved: 2026-03-06T19:56:15.891Z
Link: CVE-2026-3660
Updated: 2026-05-26T19:19:14.090Z
Status : Undergoing Analysis
Published: 2026-05-26T19:16:27.707
Modified: 2026-05-26T21:16:36.883
Link: CVE-2026-3660
No data.
OpenCVE Enrichment
Updated: 2026-05-26T22:00:14Z