VendorsIBMengineering_requirements_management_doorsall versions
Vulnerabilities

IBM Engineering Requirements Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2018-1457
An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.
Published 2018-06-27 · Modified
9.8EPSS 0.025
CVE-2023-50304
IBM Engineering Requirements Management DOORS XML external entity injection
Published 2024-07-18 · Modified
8.2EPSS 0.006
CVE-2017-1545
IBM Doors Web Access 9.5 and 9.6 could allow an attacker with physical access to the system to log into the application using previously stored credentials. IBM X-Force ID: 130914.
Published 2018-01-26 · Modified
6.8EPSS 0.004
CVE-2023-28949
IBM Engineering Requirements Management cross-site request forgery
Published 2024-03-01 · Modified
6.5EPSS 0.002
CVE-2024-43190
IBM Engineering Requirements Management DOORS weak authentication
Published 2025-07-07 · Analyzed
5.9EPSS 0.003
CVE-2017-1516
IBM Doors Web Access 9.5 and 9.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 129826.
Published 2018-01-26 · Modified
5.4EPSS 0.012
CVE-2017-1532
IBM DOORS 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130411.
Published 2018-01-26 · Modified
5.4EPSS 0.009
CVE-2017-1540
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130808.
Published 2018-01-26 · Modified
5.4EPSS 0.009
CVE-2017-1563
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131763.
Published 2018-01-26 · Modified
5.4EPSS 0.009
CVE-2017-1567
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.
Published 2018-01-26 · Modified
5.4EPSS 0.009
CVE-2023-50305
IBM Engineering Requirements Management information disclosure
Published 2024-03-01 · Modified
5.1EPSS 0.002
CVE-2023-28525
IBM Engineering Requirements Management cross-site scripting
Published 2024-03-01 · Modified
4.8EPSS 0.003
CVE-2017-1515
IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825.
Published 2018-01-26 · Modified
4.3EPSS 0.012