CVE-2024-25039: IBM Engineering Requirements Management Doors Web Access

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.

Affected products

  • IBM Engineering Requirements Management Doors Web Access: from 9.6.1.1, up to and including 9.6.1.13; from 9.7.2.1, up to and including 9.7.2.11

Published 2026-07-30. Last modified 2026-10-02.