CVE-2025-2138: IBM Engineering Requirements Management Doors Next data modification
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1
could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.
Other sources
IBM Engineering Requirements Management DOORS Next could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.2Patch ifix 36 - Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.3Patch ifix 19 or newer - Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.1.0Patch ifix 05 or newer
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2138?
CVE-2025-2138 is considered a moderate severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2025-2138?
To fix CVE-2025-2138, upgrade IBM Engineering Requirements Management DOORS Next to the latest version available beyond 7.1.
Who is affected by CVE-2025-2138?
Users of IBM Engineering Requirements Management DOORS Next versions 7.0.2, 7.0.3, and 7.1 are affected by CVE-2025-2138.
What type of attack does CVE-2025-2138 allow?
CVE-2025-2138 allows authenticated users to delete comments from other users due to improper security enforcement.
Is CVE-2025-2138 related to network security?
Yes, CVE-2025-2138 involves network security as it affects authenticated users over the network.