Executive brief
IBM Engineering Requirements Management DOORS is a tool used by organizations to manage complex product requirements and compliance. A vulnerability in its web access component allows an attacker to keep network connections open indefinitely, potentially leading to a 'Slowloris' attack. This can exhaust the server's resources, making the system unresponsive and preventing legitimate users from accessing critical project data.
Technical details
The vulnerability is classified as Uncontrolled Resource Consumption (CWE-400). The affected versions of IBM DOORS and DOORS Web Access fail to properly limit the duration or length of incoming HTTP connections. An unauthenticated remote attacker can exploit this by initiating multiple 'Slowloris' style connections—sending partial HTTP requests and keeping them open as long as possible. This exhausts the server's concurrent connection pool, leading to a Denial of Service (DoS) condition. Users are advised to refer to the IBM security bulletin for patch information.
Affected products
- IBM Engineering Requirements Management DOORS 9.7.2.1 - 9.7.2.11, 9.6.1.1 - 9.6.1.13
- IBM Engineering Requirements Management DOORS Web Access 9.7.2.1 - 9.7.2.11, 9.6.1.1 - 9.6.1.13
Timeline
- 2026-07-30: advisory: Initial disclosure by IBM and NVD publication