Vulnerability Details CVE-2026-3660
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-3660
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.0.3
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.1.0
-
cpe:2.3:a:ibm:engineering_lifecycle_management:7.2.0