IBM Engineering Requirements Management DOORS Next是美国国际商业机器(IBM)公司的一个可扩展的解决方案。该解决方案可帮助您捕获、跟踪、分析和管理系统与高级 IT 应用开发。 IBM Engineering Requirements Management DOORS Next 7.1版本和7.2版本存在安全漏洞,该漏洞源于访问控制不当,可能导致经过身份验证的用户查看和编辑超出其授权范围的数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Engineering Requirements Management DOORS Next | 7.1 ~ rage Scale 5.2.3.0 - 5.2.3.5 |
cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.1:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1567 | 7.1 HIGH | IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vu |
| CVE-2025-14604 | 6.6 MEDIUM | The following vulnerabilities, which may affect IBM Storage Scale when a directory has a s |
| CVE-2025-13616 | 6.5 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to sensitive information leak due to HTTP re |
| CVE-2026-2606 | 6.5 MEDIUM | IBM webMethods API Management fails to validate user input and enables unauthorized arbitr |
| CVE-2025-13686 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-13687 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-13688 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-36364 | 6.2 MEDIUM | IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request que |
| CVE-2025-13490 | 5.9 MEDIUM | IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime op |
| CVE-2025-36363 | 5.9 MEDIUM | IBM DevOps Plan is vulnerable to Excessive Authentication Attempts |
| CVE-2025-14480 | 5.1 MEDIUM | IBM Aspera faspio Gateway 1.3.7 has addressed a vulnerability affected by weak cryptograph |
| CVE-2025-14923 | 4.7 MEDIUM | IBM WebSphere Application Server Liberty could provide weaker than expected security |
| CVE-2026-1265 | 4.3 MEDIUM | IBM InfoSphere Information Server is vulnerable due to sensitive information written to a |
| CVE-2025-14456 | IBM MQ Appliance uses weaker than expected cryptographic algorithms | |
| CVE-2026-1713 | IBM MQ is affected by an authority vulnerablility |
No comments yet