PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0152 IBM CVE debrief

IBM Engineering Requirements Management DOORS and DOORS Web Access is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 through 9.6.1.13. Defenders should assess potential exposure and impact, especially in systems with untrusted or unauthenticated access to the Web UI.

Vendor
IBM
Product
Engineering Requirements Management DOORS and DOORS Web Access
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-09-29
Advisory published
2026-07-30
Advisory updated
2026-09-29

Who should care

Defenders responsible for systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI, should assess potential exposure and impact.

Why it matters

Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI. The vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. However, there is limited information on potential exploitation or impact, and further verification is required.

  • Potential credentials disclosure within trusted sessions.
  • Possible alteration of intended Web UI functionality.
  • Need for verification of system configurations and versions against affected ranges.
  • Potential for unauthenticated attackers to embed arbitrary JavaScript code.

Technical summary

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 through 9.6.1.13. Defenders should assess potential exposure and impact, especially in systems with untrusted or unauthenticated access to the Web UI.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI.

Recommended defensive actions

  • Verify exposure by checking system configurations and versions against affected ranges (9.6.1.1-9.6.1.13 and 9.7.2.1-9.7.2.11).
  • Assess potential impact on systems with untrusted or unauthenticated access to the Web UI.
  • Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent cross-site scripting attacks.
  • Monitor for suspicious activity and potential credentials disclosure within trusted sessions.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including affected versions and a CVSS score of 6.1. However, there is limited information on potential exploitation or impact. Defenders should verify system configurations and versions against affected ranges (9.6.1.1-9.6.1.13 and 9.7.2.1-9.7.2.11) and assess potential impact on systems with untrusted or unauthenticated access to the Web UI. The source details are limited, so explicit evidence-limit language and defensive verification tasks are required.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-0152 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-0152

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-0152 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0152

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.