PT-2026-66553 · Ibm · Ibm Engineering Requirements Management Doors Next+1

CVE-2024-25039

·

Published

2026-07-30

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.7.2.1 through 9.7.2.11 IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.6.1.1 through 9.6.1.13
Description Failure to limit connection length allows for a Slowloris HTTP denial of service attack, which can cause the web server to become unresponsive. Slowloris is a type of attack that keeps many connections to the target web server open and holds them open as long as possible by sending partial HTTP requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25039

Affected Products

Doors Web Access
Ibm Engineering Requirements Management Doors Next