IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
| Software | From | Fixed in |
|---|---|---|
| ibm / engineering_requirements_management_doors | 9.6 | 9.6.1.13.x |
| ibm / engineering_requirements_management_doors | 9.7.2.9 | 9.7.2.9.x |
| ibm / engineering_requirements_management_doors_web_access | 9.6 | 9.6.1.13.x |
| ibm / engineering_requirements_management_doors_web_access | 9.7.2.9 | 9.7.2.9.x |