{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-27253", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2024-02-22T01:26:15.968Z", "datePublished": "2026-08-12T21:23:03.460Z", "dateUpdated": "2026-08-13T19:26:28.054Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-08-12T21:23:03.460Z" }, "title": "IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-287", "description": "CWE-287 Improper Authentication", "type": "CWE" } ] } ], "affected": [ { "vendor": "IBM", "product": "DOORS Next", "versions": [ { "status": "affected", "version": "7.0.3", "lessThanOrEqual": "7.0.3 Interim Fix 018", "versionType": "semver" } ], "cpes": [ "cpe:2.3:a:ibm:doors_next:7.0.3:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:doors_next:7.0.3:interim_fix_018:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/7282705", "tags": [ "vendor-advisory", "patch" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "CRITICAL", "baseScore": 10, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" } } ], "solutions": [ { "lang": "en", "value": "IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below:\n\n\n\nIBM recommends customers on ELM 7.0.1, 7.0.2 or any version below 7.0.3 to upgrade your products to Maintenance release 7.0.3 and apply below fix.\n\n\n\nOptionally, upgrade to the latest 7.2.0 version.\n\nAffected Product(s)Version(s)Remediation/Fix/Instructions\n\nIBM Engineering Requirements Management DOORS Next\n\n7.0.3Download and install  iFix019 https://www.ibm.com/support/fixcentral/swg/downloadFixes  or later", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

IBM strongly recommends addressing the vulnerability now by upgrading to iFixes detailed below:

IBM recommends customers on ELM 7.0.1, 7.0.2 or any version below 7.0.3 to upgrade your products to Maintenance release 7.0.3 and apply below fix.

Optionally, upgrade to the latest 7.2.0 version.

Affected Product(s)Version(s)Remediation/Fix/Instructions

IBM Engineering Requirements Management DOORS Next

7.0.3Download and install iFix019 or later
" } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-13T19:22:12.406760Z", "id": "CVE-2024-27253", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-13T19:26:28.054Z" } } ] } }