CVE-2024-27253 PUBLISHED

IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request

Assigner: ibm
Reserved: 22.02.2024 Published: 12.08.2026 Updated: 12.08.2026

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor IBM
Product DOORS Next
Versions
  • affected from 7.0.3 to 7.0.3 Interim Fix 018 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below:

IBM recommends customers on ELM 7.0.1, 7.0.2 or any version below 7.0.3 to upgrade your products to Maintenance release 7.0.3 and apply below fix.

Optionally, upgrade to the latest 7.2.0 version.

Affected Product(s)Version(s)Remediation/Fix/Instructions

IBM Engineering Requirements Management DOORS Next

7.0.3Download and install  iFix019 https://www.ibm.com/support/fixcentral/swg/downloadFixes  or later

References

Problem Types

  • CWE-287 Improper Authentication CWE