CVE-2024-43190

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
07/07/2025
Last modified:
20/08/2025

Description

IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:engineering_requirements_management_doors:*:*:*:*:*:*:*:* 9.6 (including) 9.6.1.13 (including)
cpe:2.3:a:ibm:engineering_requirements_management_doors:9.7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:*:*:*:*:*:*:*:* 9.6 (including) 9.6.1.13 (including)
cpe:2.3:a:ibm:engineering_requirements_management_doors_web_access:9.7.2.9:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools