Loading vulnerability details…
CVSS v3.1
5.7
EPSS
0.12%
Published
Oct 12, 2025
Modified
Oct 16, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NWeaknesses (CWE)
Affected Products (6)
References (1)