CVE-2024-43190

IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
References
Link Resource
https://www.ibm.com/support/pages/node/7238992 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:engineering_requirements_management_doors:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:9.7.2.9:*:*:*:*:*:*:*

History

20 Aug 2025, 16:27

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7238992 - () https://www.ibm.com/support/pages/node/7238992 - Vendor Advisory
First Time Ibm engineering Requirements Management Doors Web Access
Ibm
Ibm engineering Requirements Management Doors
CPE cpe:2.3:a:ibm:engineering_requirements_management_doors:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:9.7.2.9:*:*:*:*:*:*:*

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) IBM Engineering Requirements Management DOORS 9.7.2.9, bajo ciertas configuraciones, podría permitir que un atacante remoto obtenga instrucciones de restablecimiento de contraseña de un usuario legítimo utilizando técnicas de intermediario.

07 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 18:15

Updated : 2025-08-20 16:27


NVD link : CVE-2024-43190

Mitre link : CVE-2024-43190

CVE.ORG link : CVE-2024-43190


JSON object : View

Products Affected

ibm

  • engineering_requirements_management_doors
  • engineering_requirements_management_doors_web_access
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password