Executive brief
IBM Engineering Requirements Management DOORS, a tool used by organizations to manage complex product requirements, is affected by a security vulnerability in its web interface. An attacker could use this flaw to run malicious scripts in a user's browser if the user visits a specially crafted link. This could allow the attacker to steal login credentials or perform unauthorized actions within the user's active session.
Technical details
IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.7.2.1 through 9.7.2.11 and 9.6.1.1 through 9.6.1.13 are vulnerable to reflected cross-site scripting (XSS). The vulnerability exists due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by persuading a user to visit a malicious URL, leading to the execution of arbitrary JavaScript code within the context of the victim's trusted session. This can result in the disclosure of sensitive information, such as session credentials, or the alteration of the Web UI's intended functionality. IBM has released a security bulletin (node 7279145) addressing this and other vulnerabilities.
Affected products
- IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, 9.6.1.1 through 9.6.1.13
Timeline
- 2026-07-30: advisory: IBM published the security bulletin.
- 2026-07-30: disclosed: CVE published to NVD.