Stored Cross-Site Scripting Vulnerability in IBM Engineering Requirements Management DOORS Next
CVE-2025-1826

5.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
7 October 2025

What is CVE-2025-1826?

IBM Engineering Requirements Management DOORS Next contains a vulnerability that enables authenticated users within the host network to inject arbitrary JavaScript into the web interface. This malicious code modification may compromise the functionality of the application, leading to unauthorized credential disclosure during trusted sessions. Mitigating this issue is crucial to protect sensitive information from potential exploitation.

Affected Version(s)

Jazz Foundation 7.0.2 <= 7.0.2 iFix034

Jazz Foundation 7.0.3 <= 7.0.3 iFix016

Jazz Foundation 7.1.0 <= 7.1.0 iFix004

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-1826 : Stored Cross-Site Scripting Vulnerability in IBM Engineering Requirements Management DOORS Next