IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T17:40:37.424Z

Reserved: 2024-12-31T19:08:58.246Z

Link: CVE-2025-0152

cve-icon Vulnrichment

Updated: 2026-07-30T17:40:09.778Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.