{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-2138","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-03-10T01:10:31.239Z","datePublished":"2025-10-12T13:37:02.296Z","dateUpdated":"2025-10-14T15:10:47.518Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.1:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"Engineering Requirements Management Doors Next","vendor":"IBM","versions":[{"status":"affected","version":"7.0.2"},{"status":"affected","version":"7.0.3"},{"status":"affected","version":"7.1"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 \n\n<span style=\"background-color: rgb(255, 255, 255);\">could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.</span>"}],"value":"IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 \n\ncould allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-602","description":"CWE-602 Client-Side Enforcement of Server-Side Security","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-10-12T13:37:02.296Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7247716"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"For IBM Engineering Requirements Management DOORS Next 7.0.2, install ifix 36.<br><br>For IBM Engineering Requirements Management DOORS Next 7.0.3, install ifix 19 or newer.<br><br>For IBM Engineering Requirements Management DOORS Next 7.1.0, install ifix 05 or newer.<br>"}],"value":"For IBM Engineering Requirements Management DOORS Next 7.0.2, install ifix 36.\n\nFor IBM Engineering Requirements Management DOORS Next 7.0.3, install ifix 19 or newer.\n\nFor IBM Engineering Requirements Management DOORS Next 7.1.0, install ifix 05 or newer."}],"source":{"discovery":"UNKNOWN"},"title":"IBM Engineering Requirements Management Doors Next data modification","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-14T15:10:41.254195Z","id":"CVE-2025-2138","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-14T15:10:47.518Z"}}]}}