CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

doors_next

26 known vulnerabilities · sorted by CVSS score

CVE-2024-41787
CRITICAL9.8

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

ibm / doors_next+1
Network
Published Jan 10, 2025
Page 1 of 2
CVE-2023-45192
HIGH8.2

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 268758.

ibm / doors_next+1
Network
Published Jun 6, 2024
CVE-2020-4965
HIGH7.5

IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2021-20351
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4856
MEDIUM5.4

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4920
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191396.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2021-20519
MEDIUM5.4

IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198441.

ibm / collaborative_lifecycle_management+37
Network
Published Apr 12, 2021
CVE-2020-4697
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186790.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2020-4857
MEDIUM5.4

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4445
MEDIUM5.4

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

ibm / doors_next+21
Network
Published Sep 2, 2020
CVE-2020-4733
MEDIUM5.4

IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188127.

ibm / collaborative_lifecycle_management+32
Network
Published Jan 8, 2021
CVE-2019-4748
MEDIUM5.4

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173174.

ibm / collaborative_lifecycle_management+19
Network
Published Jul 16, 2020
CVE-2020-4281
MEDIUM5.4

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176141.

ibm / doors_next+3
Network
Published Jun 19, 2020
CVE-2020-4297
MEDIUM5.4

IBM DOORS Next Generation (DNG/RRC) 6.0.2, 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176474.

ibm / doors_next+3
Network
Published Jun 19, 2020
CVE-2020-4522
MEDIUM5.4

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182397.

ibm / doors_next+21
Network
Published Sep 2, 2020
CVE-2020-4866
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2021-20340
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4975
MEDIUM5.4

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4863
MEDIUM5.4

IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.

ibm / doors_next+22
Network
Published Mar 4, 2021
CVE-2020-4546
MEDIUM5.4

IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.

ibm / doors_next+21
Network
Published Sep 2, 2020