Client-Side Enforcement of Server-Side Security in IBM Engineering Requirements Management DOORS Next - CVE-2025-2138
Published: October 15, 2025
Vulnerability identifier: #VU117182
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-2138
CWE-ID: CWE-602
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: IBM Corporation
Affected software:
IBM Engineering Requirements Management DOORS Next
IBM Engineering Requirements Management DOORS Next
Detailed vulnerability description
The vulnerability allows an adjacent user to gain access to modify data on the system.
The vulnerability exists due to client-side enforcement of server-side security. An adjacent user can gain unauthorized access to delete comments from other users.
How to mitigate CVE-2025-2138
Install updates from vendor's website.