SB2025101597 - Multiple vulnerabilities in IBM Engineering Requirements Management DOORS Next
Published: October 15, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Client-Side Enforcement of Server-Side Security (CVE-ID: CVE-2025-2139)
2) Client-Side Enforcement of Server-Side Security (CVE-ID: CVE-2025-2138)
The vulnerability allows an adjacent user to gain access to modify data on the system.
The vulnerability exists due to client-side enforcement of server-side security. An adjacent user can gain unauthorized access to delete comments from other users.
3) Origin validation error (CVE-ID: CVE-2025-2140)
The vulnerability allows a remote user to modify data on the system.
The vulnerability exists due to improper verification of source data. A remote user can trigger origin validation error and spoof email identity of the sender.
4) Uncontrolled Recursion (CVE-ID: CVE-2025-33096)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to uncontrolled recursion. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.