CVE-2024-27253

10.0

IBM · DOORS Next

IBM DOORS Next contains an authentication bypass vulnerability, allowing an attacker to perform unauthorized activities within the system.

Executive summary

A critical authentication bypass vulnerability in IBM DOORS Next allows attackers to gain unauthorized access and perform sensitive operations.

Vulnerability

The application suffers from improper authentication (CWE-287), which allows a user to bypass security logic and perform unauthorized operations. While the description mentions an authenticated user, the CVSS vector indicates the attack is possible without prior authentication (PR:N).

Business impact

With a CVSS score of 10.0, this vulnerability represents the highest level of risk to business operations. Exploitation could lead to complete unauthorized control over engineering requirements, potential data theft, or the modification of critical documentation, which could have severe consequences for product safety and regulatory compliance.

Remediation

Immediate Action: Upgrade to the latest version or apply iFix019 for version 7.0.3 as instructed by IBM.

Proactive Monitoring: Review application access logs for unusual administrative activity or access requests from unexpected user accounts or IP addresses.

Compensating Controls: Implement strict network access controls to limit access to the DOORS Next interface to authorized internal networks only.

Exploitation status

Public Exploit Available: No (unknown).

Analyst recommendation

The critical severity of this authentication bypass requires immediate attention. Organizations must prioritize upgrading their DOORS Next deployment to the recommended fix level to eliminate the risk of unauthorized system access and potential data manipulation.

More IBM CVEs