IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54752 IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
Fixes

Solution

IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin. For The IBM Engineering Requirements Management DOORS/DWA product versions 9.7.x, install the fix pack 9.7.2.10. You can download the fix pack for 9.7.2.10 from Fix Central.


Workaround

No workaround given by the vendor.

History

Wed, 20 Aug 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm engineering Requirements Management Doors Web Access
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:9.7.2.9:*:*:*:*:*:*:*
Vendors & Products Ibm engineering Requirements Management Doors Web Access

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00033}

epss

{'score': 0.00043}


Tue, 08 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
Description IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
Title IBM Engineering Requirements Management DOORS weak authentication
First Time appeared Ibm
Ibm engineering Requirements Management Doors
Weaknesses CWE-640
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.9:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Requirements Management Doors
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-24T11:31:35.546Z

Reserved: 2024-08-07T13:29:48.159Z

Link: CVE-2024-43190

cve-icon Vulnrichment

Updated: 2025-07-08T13:38:12.624Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-07T18:15:25.440

Modified: 2025-08-20T16:27:29.470

Link: CVE-2024-43190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.