{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-0152", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2024-12-31T19:08:58.246Z", "datePublished": "2026-07-30T16:57:15.862Z", "dateUpdated": "2026-07-30T17:40:37.424Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-07-30T16:57:15.862Z" }, "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-79", "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "type": "CWE" } ] } ], "affected": [ { "vendor": "IBM", "product": "Engineering Requirements Management DOORS and DOORS Web Access", "versions": [ { "status": "affected", "version": "9.7.2.1", "lessThanOrEqual": "9.7.2.11", "versionType": "semver" }, { "status": "affected", "version": "9.6.1.1", "lessThanOrEqual": "9.6.1.13", "versionType": "semver" } ], "cpes": [ "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/7279145", "tags": [ "vendor-advisory", "patch" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 6.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" } } ], "solutions": [ { "lang": "en", "value": "IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for 9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes from Fix Central.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.
For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.
You can download the fix pack for 9.7.2.12 from Fix Central.
" } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-30T17:39:59.567276Z", "id": "CVE-2025-0152", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-30T17:40:37.424Z" } } ] } }