PatchSiren cyber security CVE debrief
CVE-2026-14979 IBM CVE debrief
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of these products should apply vendor remediation to prevent potential denial of service attacks. The vulnerability affects the DOORS component, which is part of the IBM Engineering Lifecycle Management suite. Affected users should review the vendor advisory and take necessary actions to protect their systems.
- Vendor
- IBM
- Product
- Engineering Lifecycle Management
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-17
- Original CVE updated
- 2026-08-11
- Advisory published
- 2026-07-17
- Advisory updated
- 2026-08-11
Who should care
Users of IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 DOORS should apply vendor remediation to prevent potential denial of service attacks. System administrators, security teams, and operators of these products should review the vendor advisory and take necessary actions to protect their systems. This includes identifying and remediating affected deployments, reviewing system configurations, and monitoring for suspicious activity.
Technical summary
The CVE-2026-14979 vulnerability is due to improper handling of XML entity expansion in IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 DOORS. This could allow a remote attacker to cause a denial of service. The vulnerability has a CVSS score of 5.3, indicating a MEDIUM severity level. Affected product deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance.
Defensive priority
Medium priority due to CVSS score of 5.3 and potential for denial of service attacks. Defenders should prioritize remediation efforts based on the severity of the vulnerability and the potential impact on their systems.
Recommended defensive actions
- Apply vendor remediation
- Inventory and monitor affected systems
- Implement compensating controls
- Review system configurations and logs for suspicious activity
- Monitor for updates from IBM
- Track exceptions and retest remediated assets
- Verify evidence of remediation and document results
Evidence notes
Evidence is limited; verify affected scope and vendor remediation status. IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 DOORS are potentially affected. Defenders should verify system configurations, review logs for suspicious activity, and monitor for updates from IBM. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14979 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14979
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14979 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14979
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7279963
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.