logo

IBM Patches Critical Authentication Bypass in Engineering Platform

ID: a7506738-b9b7-583d-88c6-90f5bdce586d

STIX ID: report--a7506738-b9b7-583d-88c6-90f5bdce586d

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Ddos

...
...

IBM released an urgent security bulletin for a critical CVE-2026-3660 in IBM Jazz Foundation (CVSS 9.8) where incorrect authorization logic allows unauthenticated remote attackers to modify server property files and bypass authentication; affected IBM Engineering Lifecycle Management versions include 7.0.3 through iFix021, 7.1.0 through iFix009, and 7.2.0 through iFix001, and IBM provides iFix updates (for example iFix022 for 7.0.3) that administrators must install immediately to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.