Skip to content
Threat Feed
critical advisory

Improper Authentication in IBM DOORS Next

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 contains an improper authentication vulnerability that allows authenticated users to bypass security logic and perform unauthorized actions.

CVE search metadata

CVE search record: CVE-2024-27253. Severity: critical. CVSS: 10.0. KEV: no. Product: DOORS Next (7.0.3). Brief: Improper Authentication in IBM DOORS Next. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-doors-auth-bypass/

IBM DOORS Next versions 7.0.3 through 7.0.3 Interim Fix 018 are affected by a critical vulnerability (CVE-2024-27253) identified as an improper authentication flaw (CWE-287). The vulnerability allows an authenticated user to bypass security logic within the application to perform unauthorized activities. Given the CVSS score of 10.0, this flaw potentially allows for full compromise of the application's confidentiality, integrity, and availability. Organizations utilizing these versions of IBM DOORS Next are urged to apply the latest security patches provided by IBM to remediate the authentication logic flaw.

Impact

The vulnerability carries a CVSS 3.1 base score of 10.0, indicating the highest level of severity. Successful exploitation permits unauthorized users to bypass existing security controls, potentially leading to unauthorized data access, modification of requirements, or administrative control over the DOORS Next environment. This vulnerability primarily affects enterprise organizations utilizing IBM's requirements management software for project development and documentation.

Recommendation

Prioritized, concrete actions for infrastructure and security teams:

  • Upgrade IBM DOORS Next installations to a version strictly beyond 7.0.3 Interim Fix 018.
  • Review application access logs for anomalous activity from low-privileged user accounts, specifically focusing on unauthorized access to administrative or high-sensitivity modules in DOORS Next.
  • Monitor authentication logs for patterns of session manipulation or bypass attempts.
  • Disable internet-facing access to the DOORS Next web interface until patching is completed to limit exposure to potential exploitation.

Immediate actions

Apply latest IBM security patches for DOORS Next

IT Operations 24h

Threat Hunt

Identify accounts performing actions outside their defined scope

T1068 high medium confidence hunt now

Data: Application audit logs