Vulnerability Details CVE-2026-14979
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.5%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-14979
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0