---
id: CVE-2025-2140
title: >-
  IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could
  allow an authenticated user on the network to spoof email identity of the
  sender due to improper verification of source data.
summary: >-
  IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could
  allow an authenticated user on the network to spoof email identity of the
  sender due to improper verification of source data.
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-346
vendor: ibm
product: engineering_requirements_management_doors_next
affected:
  - engineering_requirements_management_doors_next = 7.0.2
  - engineering_requirements_management_doors_next = 7.0.3
  - engineering_requirements_management_doors_next = 7.1
published: '2025-10-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2140'
references:
  - url: 'https://www.ibm.com/support/pages/node/7247716'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00124
epssPercentile: 0.01884
ingestedAt: '2026-10-08T13:42:55.119Z'
---

## Overview

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.

## Affected

- `engineering_requirements_management_doors_next = 7.0.2`
- `engineering_requirements_management_doors_next = 7.0.3`
- `engineering_requirements_management_doors_next = 7.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
