CVE-2025-2138
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-12
Last updated on: 2025-10-16
Assigner: IBM Corporation
Description
Description
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1
could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
| ibm | engineering_requirements_management_doors_next | 7.0.2 |
| ibm | engineering_requirements_management_doors_next | 7.0.3 |
| ibm | engineering_requirements_management_doors_next | 7.1 |
| ibm | aix | * |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-602 | The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. |