CVE-2026-3660
Description
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated remote attacker can modify server property files in IBM Engineering Lifecycle Management (Jazz Foundation) 7.0.3–7.2.0, leading to authentication bypass.
Vulnerability
IBM Engineering Lifecycle Management – Jazz Foundation versions 7.0.3 (through iFix021), 7.1.0 (through iFix009), and 7.2.0 (through iFix001) contain an incorrect authorization vulnerability (CWE-863) that allows an unauthenticated remote attacker to update server property files [1]. By modifying these configuration files, the attacker can bypass authentication controls and gain unauthorized access to the application.
Exploitation
An attacker can exploit this vulnerability over the network without any authentication or user interaction. The attack complexity is low because the vulnerable endpoint or mechanism that permits writing to server property files is exposed without proper access controls [1]. No special privileges or prior access are required.
Impact
Successful exploitation leads to authentication bypass, giving the attacker the ability to gain unauthorized access to the IBM Engineering Lifecycle Management application. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a compromise of confidentiality, integrity, and availability at a high severity level [1].
Mitigation
IBM has released iFixes to address this vulnerability: iFix022 for version 7.0.3, iFix010 for version 7.1.0, and iFix002 for version 7.2.0 [1]. No workarounds are available [1]. Organizations should apply the appropriate iFix as soon as possible to prevent exploitation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=7.2.0 Interim Fix 001
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.