{"api_version":"1","generated_at":"2026-07-30T20:37:41+00:00","cve":"CVE-2025-0152","urls":{"html":"https://cve.report/CVE-2025-0152","api":"https://cve.report/api/cve/CVE-2025-0152.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-0152","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-0152"},"summary":{"title":"IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities","description":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-07-30 19:16:57","updated_at":"2026-07-30 19:31:02"},"problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7279145","name":"https://www.ibm.com/support/pages/node/7279145","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-0152","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0152","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Engineering Requirements Management DOORS and DOORS Web Access","version":"affected 9.7.2.1 9.7.2.11 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Engineering Requirements Management DOORS and DOORS Web Access","version":"affected 9.6.1.1 9.6.1.13 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for  9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-0152","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-30T17:39:59.567276Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-30T17:40:37.424Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*"],"product":"Engineering Requirements Management DOORS and DOORS Web Access","vendor":"IBM","versions":[{"lessThanOrEqual":"9.7.2.11","status":"affected","version":"9.7.2.1","versionType":"semver"},{"lessThanOrEqual":"9.6.1.13","status":"affected","version":"9.6.1.1","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</p>"}],"value":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T16:57:15.862Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7279145"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.</strong></p><p>For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions <strong>9.6.1.1 to 9.6.1.13</strong> and <strong>9.7.2.1 to 9.7.2.11</strong>, install the fix pack <strong>9.7.2.12</strong>.</p><p>You can download the fix pack for <a href=\"https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Engineering&amp;product=ibm/Rational/IBM+Engineering+Requirements+Management+DOORS&amp;release=9.7.2.12&amp;platform=All&amp;function=fixId&amp;fixids=9.7.2.12-DOORS-fixpack&amp;includeRequisites=0&amp;includeSupersedes=0&amp;downloadMethod=http&amp;login=true\" rel=\"noopener noreferrer nofollow\">9.7.2.12</a> from Fix Central.</p>"}],"value":"IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for  9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central."}],"title":"IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2025-0152","datePublished":"2026-07-30T16:57:15.862Z","dateReserved":"2024-12-31T19:08:58.246Z","dateUpdated":"2026-07-30T17:40:37.424Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 19:16:57","lastModifiedDate":"2026-07-30 19:31:02","problem_types":["CWE-79","CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T17:39:59.567276Z","id":"CVE-2025-0152","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"152","Ordinal":"1","Title":"IBM Engineering Requirements Management DOORS and DOORS Web Acce","CVE":"CVE-2025-0152","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"152","Ordinal":"1","NoteData":"IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.","Type":"Description","Title":"IBM Engineering Requirements Management DOORS and DOORS Web Acce"}]}}}