Codebeamer
Intland · 8 CVEs
PTC Codebeamer Cross site scripting
Aug 29, 2023
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remem…
Jun 8, 2021
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to pe…
Jun 8, 2021
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger a…
Jun 8, 2021
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM…
Dec 7, 2020
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java clas…
Apr 2, 2020
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature…
Mar 30, 2020
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
Mar 30, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-4296 | PTC Codebeamer Cross site scripting | HIGH | 0.76% | Aug 29, 2023 |
| CVE-2020-26515 | An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the a… | HIGH | 0.51% | Jun 8, 2021 |
| CVE-2020-26517 | A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebD… | MEDIUM | 0.54% | Jun 8, 2021 |
| CVE-2020-26516 | A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and c… | HIGH | 0.85% | Jun 8, 2021 |
| CVE-2020-26513 | An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is pars… | MEDIUM | 0.92% | Dec 7, 2020 |
| CVE-2019-20635 | codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields. | MEDIUM | 0.88% | Apr 2, 2020 |
| CVE-2019-19912 | In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to… | MEDIUM | 0.80% | Mar 30, 2020 |
| CVE-2019-19913 | In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter. | MEDIUM | 0.70% | Mar 30, 2020 |
Showing 1 to 8 of 8 CVEs