IBM Doors Next
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Doors Next.
By the Year
In 2026 there have been 0 vulnerabilities in IBM Doors Next. Last year, in 2025 Doors Next had 6 security vulnerabilities published. Right now, Doors Next is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 6 | 6.90 |
| 2024 | 1 | 8.20 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 7 | 5.73 |
It may take a day or so for new Doors Next vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Doors Next Security Vulnerabilities
IBM Doors Next 7.0.2-7.1 Email Spoof via Unverified Sender Source (CVE-2025-2140)
CVE-2025-2140
5.7 - Medium
- October 12, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
Origin Validation Error
IBM Doors Next 7.0.x: Authenticated DoS via Recursive File Upload
CVE-2025-33096
6.5 - Medium
- October 12, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.
Stack Exhaustion
Stored XSS via Web UI in IBM DOORS Next 7.0.27.1.0 iFixes
CVE-2025-1826
5.4 - Medium
- October 07, 2025
IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, and 7.1.0 to 7.1.0 iFix004) is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users on the host network to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
XSS
IBM DOORS Next 7.0.2-7.1 Unverified File Download Allowing Malicious Execution
CVE-2024-43169
6.5 - Medium
- March 03, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code.
Download of Code Without Integrity Check
IBM Engineering Req Mgmt DOORS Next 7.0.2/7.0.3/7.1 Remote File Retrieval
CVE-2024-41770
7.5 - High
- March 03, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.
Insufficiently Protected Credentials
IBM DOORS Next 7.0.2/7.0.3 Remote RCE via Race Condition
CVE-2024-41787
9.8 - Critical
- January 10, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.
TOCTTOU
XXE in IBM DOORS Next 7.0.2/7.0.3 XML vulnerability
CVE-2023-45192
8.2 - High
- June 06, 2024
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 268758.
XXE
IBM Jazz Team Server products are vulnerable to stored cross-site scripting
CVE-2020-4920
5.4 - Medium
- April 12, 2021
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.
XSS
IBM Jazz Team Server products contain an undisclosed vulnerability
CVE-2020-4964
4.3 - Medium
- April 12, 2021
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. IBM X-Force ID: 192419.
IBM Jazz Team Server products use weaker than expected cryptographic algorithms
CVE-2020-4965
7.5 - High
- April 12, 2021
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
Use of a Broken or Risky Cryptographic Algorithm
IBM Jazz Team Server products are vulnerable to cross-site scripting
CVE-2021-20519
- April 12, 2021
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.
IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-20340
- March 04, 2021
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.
IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-20350
- March 04, 2021
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.
IBM Engineering products are vulnerable to cross-site scripting
CVE-2021-20351
- March 04, 2021
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Doors Next or by IBM? Click the Watch button to subscribe.