Description
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Engineering Requirements Management DOORS and DOORS Web Access does not enforce a maximum request length for certain HTTP connections, which can be abused to launch a Slowloris‑style denial‑of‑service attack. An attacker can send a stream of incomplete HTTP requests to exhaust the server’s connection pool, leaving legitimate users unable to access the application. This defect is an instance of Uncontrolled Resource Consumption (CWE‑400) and results in the unavailability of the system by denying service.

Affected Systems

The vulnerability impacts IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.6.1.1 through 9.6.1.13 and 9.7.2.1 through 9.7.2.11 on all platforms supported by IBM. Updated versions should replace the affected releases to mitigate the risk.

Risk and Exploitability

The CVSS v3.1 score of 7.5 signals a high severity risk. The EPSS score of less than 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote via the public HTTP interface; an attacker needs only to flood the server with slow HTTP requests to trigger resource exhaustion and cause unresponsiveness.

Generated by OpenCVE AI on August 4, 2026 at 11:41 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin. For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12. You can download the fix pack for 9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central.


OpenCVE Recommended Actions

  • Install IBM Engineering Requirements Management DOORS and DOORS Web Access fix pack 9.7.2.12 for all affected versions.
  • Restart the web services to apply the new configuration.
  • Configure HTTP connection limits or apply rate‑limiting on the web server to reduce the impact of slow HTTP request floods.

Generated by OpenCVE AI on August 4, 2026 at 11:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm engineering Requirements Management Doors Web Access
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:*
Vendors & Products Ibm engineering Requirements Management Doors Web Access

Fri, 31 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
Title IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Engineering Requirements Management Doors And Doors Web Access Engineering Requirements Management Doors Web Access
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T23:05:09.914Z

Reserved: 2024-02-03T14:49:24.713Z

Link: CVE-2024-25039

cve-icon Vulnrichment

Updated: 2026-07-31T23:05:03.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:16:56.507

Modified: 2026-08-12T18:43:21.023

Link: CVE-2024-25039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption