Impact
IBM DOORS Next versions 7.0.3 and the interim fix 018 contain a flaw in the Reviews delete request handling that permits an authenticated user to bypass the intended security checks. Because the vulnerability is tied to an authenticated session, it effectively becomes a privilege escalation or authorization bypass weakness, aligning with CWE-287. An attacker who has legitimate credentials can exploit this flaw to perform actions they should not be allowed to, potentially manipulating or deleting reviews without proper authorization.
Affected Systems
IBM Engineering Requirements Management DOORS Next is impacted. Vulnerable releases include 7.0.3 and 7.0.3 Interim Fix 018. The remediation described by IBM is applying iFix019 or later to 7.0.3, and optionally upgrading to the latest 7.2.0 version.
Risk and Exploitability
The CVSS score of 10 indicates a critical impact, and the exploitability is limited to users with valid authentication, meaning that internal attackers or compromised user accounts would be the primary threat actors. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it may not yet be widely exploited in the wild. Nonetheless, the severity of the flaw demands prompt action.
OpenCVE Enrichment