CVE-2024-25039: IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities
IBM DOORS Web Access do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
Other sources
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Requirements Management DOORS and DOORS Web Accessto a version that resolves this vulnerability.Fixed in 9.7.2.12
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25039?
CVE-2024-25039 has a high severity score of 7.5.
How can I fix CVE-2024-25039?
To fix CVE-2024-25039, upgrade to the latest version of IBM Engineering Requirements Management DOORS or DOORS Web Access.
What impact does CVE-2024-25039 have on IBM DOORS?
CVE-2024-25039 allows for a Slowloris HTTP denial of service attack that can make the web server unresponsive.
Is my version of IBM DOORS vulnerable to CVE-2024-25039?
Versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 of IBM DOORS are affected by CVE-2024-25039.
What is the type of attack associated with CVE-2024-25039?
CVE-2024-25039 is associated with a Slowloris HTTP denial of service attack.