CVE-2026-14979
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Engineering Lifecycle Management | 7.0.3 ( Interim Fix 001 <= ) Interim Fix 021 | affected |
| IBM | Engineering Lifecycle Management | 7.1.0 ( Interim Fix 001 <= ) Interim Fix 009 | affected |
| IBM | Engineering Lifecycle Management | 7.2.0 and 7.2.0 Interim Fix 001 | affected |
Weaknesses
- CWE-776: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.