Cross-Site Scripting Vulnerability in IBM Engineering Requirements Management DOORS
CVE-2025-0152

6.1MEDIUM

What is CVE-2025-0152?

The IBM Engineering Requirements Management DOORS and DOORS Web Access products are susceptible to cross-site scripting vulnerabilities across multiple versions. An unauthenticated attacker could exploit this vulnerability by injecting arbitrary JavaScript code into the Web UI. This could disrupt normal functionality and potentially lead to unauthorized access or disclosure of sensitive user credentials within an established session. Users are advised to review the available patches to mitigate this risk effectively.

Affected Version(s)

Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 <= 9.7.2.11

Engineering Requirements Management DOORS and DOORS Web Access 9.6.1.1 <= 9.6.1.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.