PatchSiren cyber security CVE debrief
CVE-2025-0152 IBM CVE debrief
IBM Engineering Requirements Management DOORS and DOORS Web Access is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 through 9.6.1.13. Defenders should assess potential exposure and impact, especially in systems with untrusted or unauthenticated access to the Web UI.
- Vendor
- IBM
- Product
- Engineering Requirements Management DOORS and DOORS Web Access
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI, should assess potential exposure and impact.
Why it matters
Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI. The vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. However, there is limited information on potential exploitation or impact, and further verification is required.
- Potential credentials disclosure within trusted sessions.
- Possible alteration of intended Web UI functionality.
- Need for verification of system configurations and versions against affected ranges.
- Potential for unauthenticated attackers to embed arbitrary JavaScript code.
Technical summary
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 through 9.6.1.13. Defenders should assess potential exposure and impact, especially in systems with untrusted or unauthenticated access to the Web UI.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on systems using IBM Engineering Requirements Management DOORS and DOORS Web Access, especially those with untrusted or unauthenticated access to the Web UI.
Recommended defensive actions
- Verify exposure by checking system configurations and versions against affected ranges (9.6.1.1-9.6.1.13 and 9.7.2.1-9.7.2.11).
- Assess potential impact on systems with untrusted or unauthenticated access to the Web UI.
- Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent cross-site scripting attacks.
- Monitor for suspicious activity and potential credentials disclosure within trusted sessions.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including affected versions and a CVSS score of 6.1. However, there is limited information on potential exploitation or impact. Defenders should verify system configurations and versions against affected ranges (9.6.1.1-9.6.1.13 and 9.7.2.1-9.7.2.11) and assess potential impact on systems with untrusted or unauthenticated access to the Web UI. The source details are limited, so explicit evidence-limit language and defensive verification tasks are required.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7279145
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.