CVE-2024-27253
10.0IBM · DOORS Next
IBM DOORS Next contains an authentication bypass vulnerability, allowing an attacker to perform unauthorized activities within the system.
Executive summary
A critical authentication bypass vulnerability in IBM DOORS Next allows attackers to gain unauthorized access and perform sensitive operations.
Vulnerability
The application suffers from improper authentication (CWE-287), which allows a user to bypass security logic and perform unauthorized operations. While the description mentions an authenticated user, the CVSS vector indicates the attack is possible without prior authentication (PR:N).
Business impact
With a CVSS score of 10.0, this vulnerability represents the highest level of risk to business operations. Exploitation could lead to complete unauthorized control over engineering requirements, potential data theft, or the modification of critical documentation, which could have severe consequences for product safety and regulatory compliance.
Remediation
Immediate Action: Upgrade to the latest version or apply iFix019 for version 7.0.3 as instructed by IBM.
Proactive Monitoring: Review application access logs for unusual administrative activity or access requests from unexpected user accounts or IP addresses.
Compensating Controls: Implement strict network access controls to limit access to the DOORS Next interface to authorized internal networks only.
Exploitation status
Public Exploit Available: No (unknown).
Analyst recommendation
The critical severity of this authentication bypass requires immediate attention. Organizations must prioritize upgrading their DOORS Next deployment to the recommended fix level to eliminate the risk of unauthorized system access and potential data manipulation.