SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-14979

MEDIUM · CVSS 5.3 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Engineering Lifecycle Management versions 7.0.3 through 7.2.0 Interim Fix 001 are vulnerable to a denial of service attack stemming from improper handling of XML entity expansion. This vulnerability could allow remote attackers to disrupt service availability. Organizations using these specific versions should prioritize applying the necessary updates to mitigate potential service interruptions.

CVE
CVE-2026-14979
Severity
MEDIUM
CVSS
5.3
EPSS
0.39%

Original NVD Description

IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.

Related CVEs

Other vulnerabilities affecting the same vendor(s)