IBM Product Security Update Advisory (CVE-2024-41787)
Overview
We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2024-41787
IBM DOORS Next Version: 7.0.2, 7.0.3
Resolved Vulnerabilities
Vulnerability that allows remote attackers to bypass security restrictions due to a race condition (CVE-2024-41787)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-41787
IBM DOORS Next versions: 7.0.2 ifix 32 or later, 7.0.3 ifix 10 or later
References
[1] Security Bulletin: IBM Engineering Requirements Management DOORS Next is vulnerable to Race Condition Format Flaw (CVE-2024-41779) and Race Condition Servlet (CVE-2024-41787)
https://www.ibm.com/support/pages/security-bulletin-ibm-engineering-requirements-management-doors-next-vulnerable-race-condition-format-flaw-cve-2024-41779-and-race-condition-servlet-cve-2024-41787