Back to CVE List

CVE-2026-3603

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Vulnerability Description

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-611
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!