Vulnerabilities (CVE)

Filtered by vendor Intland Subscribe
Filtered by product Codebeamer Application Lifecycle Management
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26515 1 Intland 1 Codebeamer Application Lifecycle Management 2022-07-12 5.0 MEDIUM 7.5 HIGH
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
CVE-2020-26516 1 Intland 1 Codebeamer Application Lifecycle Management 2021-06-15 6.8 MEDIUM 8.8 HIGH
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.