VulnSea

engineering_requirements_management_doors_next vulnerabilities

CVEs whose affected-version data names the engineering_requirements_management_doors_next package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2025-33096Medium· 6.5
12mo ago

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.

▾ Sunlitibm · engineering_requirements_management_doors_nextEPSS 0.31%via NVD
CVE-2025-2140Medium· 5.7
12mo ago

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.

▾ Sunlitibm · engineering_requirements_management_doors_nextEPSS 0.12%via NVD
CVE-2025-2139Low· 3.5
12mo ago

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.

▾ Sunlitibm · engineering_requirements_management_doors_nextEPSS 0.18%via NVD
CVE-2025-2138Low· 3.5
12mo ago

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.

▾ Sunlitibm · engineering_requirements_management_doors_nextEPSS 0.18%via NVD
engineering_requirements_management_doors_next vulnerabilities (CVEs) · VulnSea