What is CVE-2025-0152?
CVE-2025-0152 is a Cross-Site Scripting (XSS) vulnerability in IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.7.2.x and 9.6.1.x. This flaw allows an unauthenticated attacker to inject arbitrary JavaScript into the Web UI, potentially altering the application's intended functionality. Affected systems should be updated with the appropriate patches.
Azərbaycanca: CVE-2025-0152, IBM Engineering Requirements Management DOORS və DOORS Web Access məhsullarının 9.7.2.x və 9.6.1.x versiyalarını təsir edən Cross-Site Scripting (XSS) zəifliyidir. Bu boşluq autentifikasiya olunmamış təcavüzkara veb interfeysdə ixtiyari JavaScript kodu yeritməyə imkan verir, nəticədə tətbiqin funksionallığını dəyişə bilər. Təsirlənən sistemləri müvafiq yamalarla yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Which software products are affected by CVE-2025-0152?
This vulnerability affects IBM Engineering Requirements Management DOORS and DOORS Web Access versions 9.7.2.x and 9.6.1.x.
How can CVE-2025-0152 be exploited?
This Cross-Site Scripting (XSS) flaw allows an unauthenticated attacker to inject arbitrary JavaScript into the Web UI.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.