PT-2026-66553 · Ibm · Ibm Engineering Requirements Management Doors Next+1
CVE-2024-25039
·
Published
2026-07-30
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.7.2.1 through 9.7.2.11
IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.6.1.1 through 9.6.1.13
Description
Failure to limit connection length allows for a Slowloris HTTP denial of service attack, which can cause the web server to become unresponsive. Slowloris is a type of attack that keeps many connections to the target web server open and holds them open as long as possible by sending partial HTTP requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doors Web Access
Ibm Engineering Requirements Management Doors Next