Skip to content
IBMCVE-2024-25039

IBM Engineering Requirements Management: denial of service

High7.5CVE-2024-25039 · Published Jul 30, 2026 · updated Aug 12, 2026

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.

IBM advisory

Affected versions

PackageAffectedFixed in
Engineering Requirements Management DOORS and DOORS Web Access
Product
>= 9.7.2.1, <= 9.7.2.11No fix yet
>= 9.6.1.1, <= 9.6.1.13No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: remote code execution
High8.5Jul 30
IBM Langflow OSS: code injection
Critical9.9Jul 30
UCD - IBM: information disclosure
Medium4.3Jul 30
IBM Langflow OSS: improper input validation
Critical9.9Jul 30
IBM Langflow OSS: attacker could access another user's private vector
High8.1Jul 30
IBM Langflow OSS: path traversal
High7.5Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.