CVE-2026-14979

Summary

IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.

Affected Software

VendorProductVersion RangeStatus
IBMEngineering Lifecycle Management7.0.3 ( Interim Fix 001 <= ) Interim Fix 021affected
IBMEngineering Lifecycle Management7.1.0 ( Interim Fix 001 <= ) Interim Fix 009affected
IBMEngineering Lifecycle Management7.2.0 and 7.2.0 Interim Fix 001affected

Weaknesses

  • CWE-776: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

References