CVE-2025-2140
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-12

Last updated on: 2025-10-16

Assigner: IBM Corporation

Description
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-12
Last Modified
2025-10-16
Generated
2026-06-16
AI Q&A
2025-10-12
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 6 associated CPEs
Vendor Product Version / Range
linux linux_kernel From 5.15.160 (inc) to 5.16 (inc)
ibm engineering_requirements_management_doors_next 7.0.2
ibm engineering_requirements_management_doors_next 7.0.3
ibm engineering_requirements_management_doors_next 7.1
ibm aix *
microsoft windows *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in IBM Engineering Requirements Management Doors Next versions 7.0.2, 7.0.3, and 7.1 allows an authenticated user on the network to spoof the email identity of the sender because the system improperly verifies the source data.

Impact Analysis

The vulnerability can impact you by allowing an authenticated user to impersonate another sender via email spoofing, which could lead to misinformation, unauthorized actions, or manipulation within the system or among users relying on email communications.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-2140. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart