VYPR

Engineering Requirements Management Doors

by IBM

CVEs (15)

  • CVE-2018-1457CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.03

    An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.

  • CVE-2024-25039HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to…

  • CVE-2023-50304HigJul 18, 2024
    risk 0.46cvss 7.1epss 0.01

    IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force…

  • CVE-2017-1545MedJan 26, 2018
    risk 0.44cvss 6.8epss 0.00

    IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored credentials. IBM X-Force ID: 130914.

  • CVE-2023-28949MedMar 1, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 251216.

  • CVE-2025-0152MedJul 30, 2026
    risk 0.40cvss 6.1epss 0.00

    IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering…

  • CVE-2024-43190MedJul 7, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.

  • CVE-2017-1567MedJan 26, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2017-1563MedJan 26, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2017-1540MedJan 26, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…

  • CVE-2017-1532MedJan 26, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130411.

  • CVE-2017-1516MedJan 26, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further…

  • CVE-2023-50305MedMar 1, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.

  • CVE-2023-28525MedMar 1, 2024
    risk 0.31cvss 4.8epss 0.00

    IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2017-1515MedJan 26, 2018
    risk 0.28cvss 4.3epss 0.01

    IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825.