IBM Engineering Lifecycle Management Jazz Foundation Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in IBM Engineering Lifecycle Management - Jazz Foundation, specifically in versions 7.0.3 (through iFix021), 7.1.0 (through iFix009), and 7.2.0 (through iFix001). This vulnerability allows an attacker with administrative privileges to execute remote code by exploiting an exposed method that lacks proper restrictions.

Impact

Exploitation of this vulnerability allows for server post-authentication remote code execution.

Remediation

Users are advised to upgrade to version 7.0.3 (iFix022), 7.1.0 (iFix010), or 7.2.0 (iFix002).

Added: May 26, 2026, 11:55 PM
Updated: May 26, 2026, 11:55 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
3.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.