{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-25039",
        "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "state": "PUBLISHED",
        "assignerShortName": "ibm",
        "dateReserved": "2024-02-03T14:49:24.713Z",
        "datePublished": "2026-07-30T18:14:16.220Z",
        "dateUpdated": "2026-07-31T23:05:09.914Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
                "shortName": "ibm",
                "dateUpdated": "2026-07-30T18:14:16.220Z"
            },
            "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-400",
                            "description": "CWE-400 Uncontrolled Resource Consumption",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "IBM",
                    "product": "Engineering Requirements Management DOORS and DOORS Web Access",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "9.7.2.1",
                            "lessThanOrEqual": "9.7.2.11",
                            "versionType": "semver"
                        },
                        {
                            "status": "affected",
                            "version": "9.6.1.1",
                            "lessThanOrEqual": "9.6.1.13",
                            "versionType": "semver"
                        }
                    ],
                    "cpes": [
                        "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.1:*:*:*:*:*:*:*",
                        "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.7.2.11:*:*:*:*:*:*:*",
                        "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.1:*:*:*:*:*:*:*",
                        "cpe:2.3:a:ibm:engineering_requirements_management_doors_and_doors_web_access:9.6.1.13:*:*:*:*:*:*:*"
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.ibm.com/support/pages/node/7279145",
                    "tags": [
                        "vendor-advisory",
                        "patch"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.5,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.\n\n\n\nFor The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions 9.6.1.1 to 9.6.1.13 and 9.7.2.1 to 9.7.2.11, install the fix pack 9.7.2.12.\n\n\n\nYou can download the fix pack for  9.7.2.12 https://www.ibm.com/support/fixcentral/swg/downloadFixes  from Fix Central.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p><strong>IBM strongly recommends addressing the vulnerabilities now by taking the actions documented in this bulletin.</strong></p><p>For The IBM Engineering Requirements Management DOORS and DOORS Web Access product versions <strong>9.6.1.1 to 9.6.1.13</strong> and <strong>9.7.2.1 to 9.7.2.11</strong>, install the fix pack <strong>9.7.2.12</strong>.</p><p>You can download the fix pack for <a href=\"https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Engineering&amp;product=ibm/Rational/IBM+Engineering+Requirements+Management+DOORS&amp;release=9.7.2.12&amp;platform=All&amp;function=fixId&amp;fixids=9.7.2.12-DOORS-fixpack&amp;includeRequisites=0&amp;includeSupersedes=0&amp;downloadMethod=http&amp;login=true\" rel=\"noopener noreferrer nofollow\">9.7.2.12</a> from Fix Central.</p>"
                        }
                    ]
                }
            ]
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-31T23:04:58.238407Z",
                                "id": "CVE-2024-25039",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-31T23:05:09.914Z"
                }
            }
        ]
    }
}