VulnerabilityModified
CVE-2023-50305
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
MEDIUM 5.1EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.
- CVSS 3.1
- 5.1 MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-521
- Affected
- ibm/engineering requirements management doors · ibm/engineering requirements management doors web access
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273336VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7124058Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273336VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7124058Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.