5.7
CVE-2025-2140
- EPSS 0.01%
- Veröffentlicht 12.10.2025 13:33:22
- Zuletzt bearbeitet 16.10.2025 14:32:22
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Engineering Requirements Management Doors Next spoofing
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Engineering Requirements Management Doors Next Version7.0.2
Ibm ≫ Engineering Requirements Management Doors Next Version7.0.3
Ibm ≫ Engineering Requirements Management Doors Next Version7.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.007 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 5.7 | 2.1 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.