IBM Product Security Update Advisory (CVE-2024-41787)

Overview

We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.

 

Affected Products

 

CVE-2024-41787

IBM DOORS Next Version: 7.0.2, 7.0.3

 

Resolved Vulnerabilities

Vulnerability that allows remote attackers to bypass security restrictions due to a race condition (CVE-2024-41787)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-41787

IBM DOORS Next versions: 7.0.2 ifix 32 or later, 7.0.3 ifix 10 or later

 

 

References

[1] Security Bulletin: IBM Engineering Requirements Management DOORS Next is vulnerable to Race Condition Format Flaw (CVE-2024-41779) and Race Condition Servlet (CVE-2024-41787)
https://www.ibm.com/support/pages/security-bulletin-ibm-engineering-requirements-management-doors-next-vulnerable-race-condition-format-flaw-cve-2024-41779-and-race-condition-servlet-cve-2024-41787