{"api_version":"1","generated_at":"2026-07-30T20:41:01+00:00","cve":"CVE-2024-25039","urls":{"html":"https://cve.report/CVE-2024-25039","api":"https://cve.report/api/cve/CVE-2024-25039.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-25039","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-25039"},"summary":{"title":"IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities","description":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-07-30 19:16:56","updated_at":"2026-07-30 19:31:02"},"problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7279145","name":"https://www.ibm.com/support/pages/node/7279145","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-25039","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25039","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Engineering Requirements Management DOORS and DOORS Web Access","version":"affected 9.7.2.1 9.7.2.11 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Engineering Requirements Management DOORS and DOORS Web Access","version":"affected 9.6.1.1 9.6.1.13 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for  9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*"],"product":"Engineering Requirements Management DOORS and DOORS Web Access","vendor":"IBM","versions":[{"lessThanOrEqual":"9.7.2.11","status":"affected","version":"9.7.2.1","versionType":"semver"},{"lessThanOrEqual":"9.6.1.13","status":"affected","version":"9.6.1.1","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.</p>"}],"value":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T18:14:16.220Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7279145"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.</strong></p><p>For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions <strong>9.6.1.1 to 9.6.1.13</strong> and <strong>9.7.2.1 to 9.7.2.11</strong>, install the fix pack <strong>9.7.2.12</strong>.</p><p>You can download the fix pack for <a href=\"https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Engineering&amp;product=ibm/Rational/IBM+Engineering+Requirements+Management+DOORS&amp;release=9.7.2.12&amp;platform=All&amp;function=fixId&amp;fixids=9.7.2.12-DOORS-fixpack&amp;includeRequisites=0&amp;includeSupersedes=0&amp;downloadMethod=http&amp;login=true\" rel=\"noopener noreferrer nofollow\">9.7.2.12</a> from Fix Central.</p>"}],"value":"IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for  9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central."}],"title":"IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2024-25039","datePublished":"2026-07-30T18:14:16.220Z","dateReserved":"2024-02-03T14:49:24.713Z","dateUpdated":"2026-07-30T18:14:16.220Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 19:16:56","lastModifiedDate":"2026-07-30 19:31:02","problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"25039","Ordinal":"1","Title":"IBM Engineering Requirements Management DOORS and DOORS Web Acce","CVE":"CVE-2024-25039","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"25039","Ordinal":"1","NoteData":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.","Type":"Description","Title":"IBM Engineering Requirements Management DOORS and DOORS Web Acce"}]}}}