CVE-2024-43190: IBM Engineering Requirements Management Doors
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
Affected products
- IBM Engineering Requirements Management Doors: from 9.6, up to and including 9.6.1.13; version 9.7.2.9 only
- IBM Engineering Requirements Management Doors Web Access: from 9.6, up to and including 9.6.1.13; version 9.7.2.9 only
Published 2025-07-07. Last modified 2026-06-17.