Client-Side Security Flaw in IBM Engineering Requirements Management Product
CVE-2025-2139

3.5LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 October 2025

What is CVE-2025-2139?

A client-side security flaw exists in IBM Engineering Requirements Management Doors that allows authenticated users within the network to delete reviews made by other users. This vulnerability arises from inadequate enforcement of server-side security policies, putting user-generated content at risk and potentially enabling malicious users to exploit this weakness for unauthorized actions.

Affected Version(s)

Engineering Requirements Management Doors Next 7.0.2

Engineering Requirements Management Doors Next 7.0.3

Engineering Requirements Management Doors Next 7.1

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2139 : Client-Side Security Flaw in IBM Engineering Requirements Management Product