Authentication Bypass Vulnerability in IBM Engineering Requirements Management DOORS Next
CVE-2025-13734
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 3 March 2026
What is CVE-2025-13734?
An authentication bypass vulnerability exists in IBM Engineering Requirements Management DOORS Next versions 7.1 and 7.2, enabling an authenticated user to access and modify sensitive data beyond their predefined permissions. This flaw compromises the integrity of user access controls, potentially leading to unauthorized data manipulation. Users should be aware of this issue and apply necessary patches provided by IBM to safeguard their systems.
Affected Version(s)
Engineering Requirements Management DOORS Next 7.1
Engineering Requirements Management DOORS Next 7.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Acknowledgement The vulnerability was reported to IBM by: Peter Backlund, Hunter Dyer, Todd Fine, Gary Huang, Dorota Kopczyk, Charles Nove, Addison Shuppy, George Thompson, Sandia National Laboratories