Filtered by vendor Intland
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-26515 | 1 Intland | 1 Codebeamer Application Lifecycle Management | 2022-07-12 | 5.0 MEDIUM | 7.5 HIGH |
| An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key. | |||||
| CVE-2020-26516 | 1 Intland | 1 Codebeamer Application Lifecycle Management | 2021-06-15 | 6.8 MEDIUM | 8.8 HIGH |
| A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests. | |||||
