Email Spoofing Vulnerability in IBM Engineering Requirements Management Doors
CVE-2025-2140

5.7MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 October 2025

What is CVE-2025-2140?

The improper verification of source data in IBM Engineering Requirements Management Doors versions 7.0.2, 7.0.3, and 7.1 may allow authenticated users on the network to impersonate the identity of email senders. This vulnerability could lead to unauthorized access to sensitive information, manipulation of communications, and a significant risk to organizational security. It is essential for users to update their systems and implement security measures to mitigate these risks.

Affected Version(s)

Engineering Requirements Management Doors Next 7.0.2

Engineering Requirements Management Doors Next 7.0.3

Engineering Requirements Management Doors Next 7.1

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2140 : Email Spoofing Vulnerability in IBM Engineering Requirements Management Doors