Impact
IBM Engineering Requirements Management DOORS and DOORS Web Access does not enforce a maximum request length for certain HTTP connections, which can be abused to launch a Slowloris‑style denial‑of‑service attack. An attacker can send a stream of incomplete HTTP requests to exhaust the server’s connection pool, leaving legitimate users unable to access the application. This defect is an instance of Uncontrolled Resource Consumption (CWE‑400) and results in the unavailability of the system by denying service.
Affected Systems
The vulnerability impacts IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.6.1.1 through 9.6.1.13 and 9.7.2.1 through 9.7.2.11 on all platforms supported by IBM. Updated versions should replace the affected releases to mitigate the risk.
Risk and Exploitability
The CVSS v3.1 score of 7.5 signals a high severity risk. The EPSS score of less than 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote via the public HTTP interface; an attacker needs only to flood the server with slow HTTP requests to trigger resource exhaustion and cause unresponsiveness.
OpenCVE Enrichment