Where
-Infinity
0

IBM Engineering Requirements Management DOORS and DOORS Web Access29 vulnerabilities

First published (updated )
Advisory
IBM-7279145

IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities

Risk 38
Severity
6.1
First published (updated )

IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities

Risk 43
Severity
7.5
First published (updated )

IBM DOORS Web Access could allow a remote attacker to obtain sensitive information when a detailed t…

Risk 18
First published (updated )

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

Risk 40
Severity
6.5
First published (updated )

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Risk 27
Severity
5.3
First published (updated )

Spring Framework Cross-site Scripting via JavaScriptUtils

Risk 47
Severity
7.1
First published (updated )

Spring Framework Denial of Service via Multipart Requests in WebFlux

Risk 35
Severity
5.9
First published (updated )

Spring Framework Escalation via Session Fixation in WebFlux

Risk 28
Severity
4.2
First published (updated )

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)

Risk 38
Severity
5.9
First published (updated )

Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default

Risk 84
Severity
8.8
First published (updated )

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal

Risk 24
Severity
4.3
First published (updated )

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass

Risk 84
Severity
8.8
First published (updated )

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector

Risk 64
Severity
8.1
First published (updated )

Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties

Risk 40
Severity
6.1
First published (updated )

Apache Tomcat: Security constraints not correctly applied

Risk 71
Severity
9.1
First published (updated )

Apache Tomcat: AJP secret compared in non-constant time

Risk 22
Severity
3.7
First published (updated )

Apache Tomcat: LockOutRealm treats user names as case-sensitive

Risk 46
Severity
7.5
First published (updated )

Apache Tomcat: Digest authenticator will authenticate any unknown user

Risk 92
Severity
9.8
First published (updated )

Apache Tomcat: HTTP/2 request headers not validated

Risk 92
Severity
9.8
First published (updated )

Apache Tomcat: WebSocket authentication header exposure

Risk 55
Severity
7.3
First published (updated )

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Risk 46
Severity
7.5
First published (updated )

Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp

Risk 93
Severity
9.8
First published (updated )

Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection

Risk 89
Severity
9.9
First published (updated )

Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia

Risk 84
Severity
8.8
First published (updated )

Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues

Risk 42
Severity
6.5
First published (updated )

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI

Risk 84
Severity
8.8
First published (updated )

Last updated 2 June 2026

Risk 27
Severity
5.3
First published (updated )

Infoleak

Risk 16
Severity
2.9
First published (updated )

Last updated 2 June 2026

Risk 31
Severity
5.3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203