---
id: CVE-2025-1826
title: "IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034,\_7.0.3 to 7.0.3 iFix016, and\_7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting"
summary: "IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034,\_7.0.3 to 7.0.3 iFix016, and\_7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated use…"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ibm
product: jazz_foundation
affected:
  - jazz_foundation = 7.0.2
  - jazz_foundation = 7.0.3
  - jazz_foundation = 7.1.0
published: '2025-10-07'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1826'
references:
  - url: 'https://www.ibm.com/support/pages/node/7247292'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06698
ingestedAt: '2026-10-08T22:11:53.797Z'
---

## Overview

IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users on the host network to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

## Affected

- `jazz_foundation = 7.0.2`
- `jazz_foundation = 7.0.3`
- `jazz_foundation = 7.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
