IBM Engineering Lifecycle Management
cpe:2.3:a:ibm:engineering_lifecycle_management:*:*:*:*:*:*:*
- 7.0.3
- 7.1.0
- 7.2.0
A remote code execution vulnerability has been identified in IBM Engineering Lifecycle Management - Jazz Foundation, specifically in versions 7.0.3 (through iFix021), 7.1.0 (through iFix009), and 7.2.0 (through iFix001). This vulnerability allows an attacker with administrative privileges to execute remote code by exploiting an exposed method that lacks proper restrictions.
Exploitation of this vulnerability allows for server post-authentication remote code execution.
Users are advised to upgrade to version 7.0.3 (iFix022), 7.1.0 (iFix010), or 7.2.0 (iFix002).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.