Remote Password Reset Exploit in IBM Engineering Requirements Management DOORS
CVE-2024-43190
5.9MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 7 July 2025
What is CVE-2024-43190?
A vulnerability in IBM Engineering Requirements Management DOORS version 9.7.2.9 allows remote attackers to exploit specific configurations to intercept and retrieve password reset instructions intended for legitimate users. This could be achieved through man-in-the-middle techniques, revealing sensitive information and compromising user accounts.
Affected Version(s)
Engineering Requirements Management DOORS 9.7.2.9