Description
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-07-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw that allows an unauthenticated attacker to embed arbitrary JavaScript code into the IBM DOORS Web UI, potentially hijacking user sessions or stealing credentials while users are logged in. The flaw arises because the application does not properly encode or validate user input before rendering it in the page, leading to the execution of attacker‑controlled scripts in the context of privileged users. This can compromise the confidentiality of stored credentials and other sensitive data presented in the UI.

Affected Systems

IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.6.1.1 through 9.6.1.13 and 9.7.2.1 through 9.7.2.11 are affected. These versions are subsumed under the CPE string entries for IBM DOORS and DOORS Web Access and are listed as vulnerable in the related advisories.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity vulnerability with moderate exploitation complexity. The EPSS score is < 1%, so the estimated exploitation probability is very low. The vulnerability is not cataloged in the CISA KEV, suggesting it has not yet been observed in widespread exploitation. Based on the description, the likely attack vector is remote via the web UI, with no authentication required, allowing attackers to deliver malicious code through crafted requests.

Generated by OpenCVE AI on August 3, 2026 at 10:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin. For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12. You can download the fix pack for 9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central.


OpenCVE Recommended Actions

  • Apply the IBM fix pack 9.7.2.12 to all affected DOORS and DOORS Web Access installations in the 9.6.1.1–9.6.1.13 and 9.7.2.1–9.7.2.11 ranges.
  • If patch deployment cannot be performed immediately, limit exposure by restricting web UI access to trusted IP ranges or applying a web‑application firewall rule that blocks or sanitizes scripts in user‑supplied input.
  • Review the application code to ensure that all data from users is properly escaped or encoded before rendering to the page, following the recommendations for CWE‑79 input validation and output encoding.

Generated by OpenCVE AI on August 3, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:*

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm engineering Requirements Management Doors Web Access
Vendors & Products Ibm engineering Requirements Management Doors Web Access

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Requirements Management Doors And Doors Web Access
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Engineering Requirements Management Doors And Doors Web Access Engineering Requirements Management Doors Web Access
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T17:40:37.424Z

Reserved: 2024-12-31T19:08:58.246Z

Link: CVE-2025-0152

cve-icon Vulnrichment

Updated: 2026-07-30T17:40:09.778Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:16:57.910

Modified: 2026-08-12T18:43:16.323

Link: CVE-2025-0152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')