Executive brief
IBM DOORS Next is a requirements management platform used by organizations to organize, track, and manage engineering requirements and project documentation. An authenticated user can exploit a vulnerability in the Review delete request function to bypass security controls and perform unauthorized activities they should not have permission to do, potentially compromising data integrity and access controls.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in the Review delete request function of IBM DOORS Next versions 7.0.3 through 7.0.3 iFix018. An authenticated user with network access to the system can bypass security logic by submitting specially crafted requests to the Review delete endpoint without proper authorization checks. The attack requires authentication and network access, with no additional user interaction needed. An attacker can perform unauthorized activities including viewing sensitive information, modifying records, and deleting reviews. The fix is available via iFix019 or later, and users are advised to upgrade immediately or move to version 7.2.0.
Affected products
- IBM DOORS Next 7.0.3 through 7.0.3 iFix018
Timeline
- 2026-08-05: disclosed
- 2026-08-05: patched: iFix019 or later available