CVE-2025-2139

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security.
References
Link Resource
https://www.ibm.com/support/pages/node/7247716 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.1:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

16 Oct 2025, 14:27

Type Values Removed Values Added
First Time Ibm aix
Microsoft
Microsoft windows
Linux
Ibm engineering Requirements Management Doors Next
Linux linux Kernel
Ibm
References () https://www.ibm.com/support/pages/node/7247716 - () https://www.ibm.com/support/pages/node/7247716 - Vendor Advisory
CPE cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.3:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_next:7.0.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*

12 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-12 14:15

Updated : 2025-10-16 14:27


NVD link : CVE-2025-2139

Mitre link : CVE-2025-2139

CVE.ORG link : CVE-2025-2139


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • engineering_requirements_management_doors_next
  • aix

microsoft

  • windows
CWE
CWE-602

Client-Side Enforcement of Server-Side Security