Engineering Lifecycle Management

Vendor:

First CVE: Jan 8, 2021 · Active for 5 years

48
Total CVEs
More Total CVEs than 97% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Engineering Lifecycle Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2021
5 years ago
Most Recent CVE
May 26, 2026
60 days ago

CVE Severity & Scoring

Engineering Lifecycle Management48 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network47 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (35.4%)
Unknown0 (0.0%)
Required31 (64.6%)
Privileges Required
Low45 (93.8%)
High1 (2.1%)
None2 (4.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthoriz
May 26, 20269.839NONO
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properl
May 26, 20267.229NONO
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnera
May 26, 20267.127NONO
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose
Mar 30, 20217.123NONO
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information co
Jun 2, 20216.522NONO
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
Jun 2, 20216.522NONO
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted re
Jun 2, 20218.822NONO
IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Managem
Feb 3, 20265.420NONO
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from t
Jun 2, 20215.420NONO
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from t
Jun 2, 20215.420NONO

Exploit Exposure

Signals from CVEs in this product scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (48 CVEs).

Media Mentions

Signals from CVEs in this product scope (48 CVEs).

Top CNAs Publishing CVEs For Engineering Lifecycle Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2.038.00.4%00
7.1.047.60.4%00
7.0.347.50.4%00
7.0.2265.70.7%00
7.0.1315.50.7%00
7.0.045.70.7%00
7.0405.50.7%00