Remote Password Reset Exploit in IBM Engineering Requirements Management DOORS
CVE-2024-43190
5.9MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 7 July 2025
What is CVE-2024-43190?
A vulnerability in IBM Engineering Requirements Management DOORS version 9.7.2.9 allows remote attackers to exploit specific configurations to intercept and retrieve password reset instructions intended for legitimate users. This could be achieved through man-in-the-middle techniques, revealing sensitive information and compromising user accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Engineering Requirements Management DOORS 9.7.2.9
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved