Description
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
Published: 2026-08-12
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM DOORS Next versions 7.0.3 and the interim fix 018 contain a flaw in the Reviews delete request handling that permits an authenticated user to bypass the intended security checks. Because the vulnerability is tied to an authenticated session, it effectively becomes a privilege escalation or authorization bypass weakness, aligning with CWE-287. An attacker who has legitimate credentials can exploit this flaw to perform actions they should not be allowed to, potentially manipulating or deleting reviews without proper authorization.

Affected Systems

IBM Engineering Requirements Management DOORS Next is impacted. Vulnerable releases include 7.0.3 and 7.0.3 Interim Fix 018. The remediation described by IBM is applying iFix019 or later to 7.0.3, and optionally upgrading to the latest 7.2.0 version.

Risk and Exploitability

The CVSS score of 10 indicates a critical impact, and the exploitability is limited to users with valid authentication, meaning that internal attackers or compromised user accounts would be the primary threat actors. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it may not yet be widely exploited in the wild. Nonetheless, the severity of the flaw demands prompt action.

Generated by OpenCVE AI on August 13, 2026 at 01:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below: IBM recommends customers on ELM 7.0.1, 7.0.2 or any version below 7.0.3 to upgrade your products to Maintenance release 7.0.3 and apply below fix. Optionally, upgrade to the latest 7.2.0 version. Affected Product(s)Version(s)Remediation/Fix/Instructions IBM Engineering Requirements Management DOORS Next 7.0.3Download and install  iFix019 https://www.ibm.com/support/fixcentral/swg/downloadFixes  or later


OpenCVE Recommended Actions

  • Apply iFix019 or a later iFix package to all installations running IBM DOORS Next 7.0.3, thereby restoring the proper authorization checks for Review deletes.
  • If feasible, upgrade the product to the latest 7.2.0 release, which incorporates the fix and additional security improvements.
  • Review and tighten the role‑based permissions for Review deletion within the system, ensuring that only users with explicit responsibility can perform delete operations.

Generated by OpenCVE AI on August 13, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
Title IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request
First Time appeared Ibm
Ibm doors Next
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:doors_next:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:doors_next:7.0.3:interim_fix_018:*:*:*:*:*:*
Vendors & Products Ibm
Ibm doors Next
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:26:28.054Z

Reserved: 2024-02-22T01:26:15.968Z

Link: CVE-2024-27253

cve-icon Vulnrichment

Updated: 2026-08-13T19:22:35.939Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T22:17:13.600

Modified: 2026-08-13T20:59:20.483

Link: CVE-2024-27253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:00:13Z

Weaknesses