CVE-2025-2139: IBM Engineering Requirements Management Doors Next security bypass
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.
Other sources
IBM Engineering Requirements Management DOORS Next could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.2Patch ifix 36 - Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.0.3Patch ifix 19 or newer - Upgrade
Upgrade
IBM Engineering Requirements Management DOORS Nextto a version that resolves this vulnerability.Fixed in 7.1.0Patch ifix 05 or newer
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2139?
CVE-2025-2139 has been assessed with a medium severity due to its potential impact on user data integrity.
How do I fix CVE-2025-2139?
To mitigate CVE-2025-2139, upgrade to the latest version of IBM Engineering Requirements Management DOORS Next that addresses this vulnerability.
Who is affected by CVE-2025-2139?
Users of IBM Engineering Requirements Management DOORS Next versions 7.0.2, 7.0.3, and 7.1 are affected by CVE-2025-2139.
What kind of attack does CVE-2025-2139 allow?
CVE-2025-2139 allows an authenticated user on the network to delete reviews from other users due to inadequate server-side security enforcement.
Is there a workaround for CVE-2025-2139?
Currently, the recommended approach to secure against CVE-2025-2139 is to apply the available updates from IBM.