CVE-2024-27253: IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
Other sources
IBM Engineering Systems Design Rhapsody - Model Manager could allow an authenticated user to bypass security logic to perform unauthorized activities.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix019 - Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.3 - Upgrade
Upgrade
IBM Engineering Systems Design Rhapsody - Model Managerto a version that resolves this vulnerability.Fixed in 7.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27253?
The severity of CVE-2024-27253 is rated as critical with a score of 10.
How do I fix CVE-2024-27253?
To fix CVE-2024-27253, upgrade to IBM Engineering Requirements Management DOORS Next version 7.0.3 Interim Fix 019 or later.
What type of access does CVE-2024-27253 affect?
CVE-2024-27253 affects authenticated users who can bypass security logic.
What software is impacted by CVE-2024-27253?
CVE-2024-27253 impacts IBM Engineering Requirements Management DOORS Next version 7.0.3 through Interim Fix 018.
What activities can be performed due to CVE-2024-27253?
Due to CVE-2024-27253, an authenticated user can perform unauthorized activities including bypassing security measures.