CVE-2024-25039
Awaiting Analysis
Awaiting Analysis - Queue
Slowloris HTTP DoS in IBM DOORS Web Access
Vulnerability report for CVE-2024-25039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-30
Last updated on: 2026-07-30
Assigner: IBM Corporation
Description
Description
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | engineering_requirements_management_doors | From 9.7.2.1 (inc) to 9.7.2.11 (inc) |
| ibm | engineering_requirements_management_doors | From 9.6.1.1 (inc) to 9.6.1.13 (inc) |
| ibm | doors_web_access | From 9.7.2.1 (inc) to 9.7.2.11 (inc) |
| ibm | doors_web_access | From 9.6.1.1 (inc) to 9.6.1.13 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |