← Back

Doors Next

doors_next

Vendor: Ibm • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Doors Next
Jun 17, 2026
Jan 10, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could expl...Show more
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.Show less
1Ibm
1Doors Next
Jun 17, 2026
Jun 6, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sen...Show more
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 268758.Show less
1Ibm
12Collaborative Lifecycle Management
Doors NextEngineering Insights+9 more
Jun 17, 2026
Apr 12, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.Show less
1Ibm
12Collaborative Lifecycle Management
Doors NextEngineering Insights+9 more
Jun 17, 2026
Apr 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
1Ibm
12Collaborative Lifecycle Management
Doors NextEngineering Insights+9 more
Jun 17, 2026
Apr 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 19241...Show more
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.Show less
1Ibm
12Collaborative Lifecycle Management
Doors NextEngineering Insights+9 more
Jun 17, 2026
Apr 12, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t...Show more
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.Show less
1Ibm
9Doors Next
Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+6 more
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.Show less
1Ibm
13Collaborative Lifecycle Management
Doors NextEngineering Insights+10 more
Jun 17, 2026
Jan 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.Show less
1Ibm
13Collaborative Lifecycle Management
Doors NextEngineering Insights+10 more
Jun 17, 2026
Jan 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.Show less
1Ibm
13Collaborative Lifecycle Management
Doors NextEngineering Insights+10 more
Jun 17, 2026
Jan 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186698.Show less
1Ibm
13Collaborative Lifecycle Management
Doors NextEngineering Insights+10 more
Jun 17, 2026
Jan 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the...Show more
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.Show less
1Ibm
13Collaborative Lifecycle Management
Doors NextEngineering Insights+10 more
Jun 17, 2026
Jan 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the...Show more
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181862.Show less
1Ibm
10Doors Next
Engineering Requirements Management Doors NextEngineering Test Management+7 more
Jun 17, 2026
Sep 2, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin...Show more
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.Show less