Intland develops CodeBeamer, a web-based collaboration and lifecycle management platform oriented toward software development teams, where its vulnerability exposure recurs consistently around web application input-handling and authentication issues. The durable signal reflects the product's browser-facing architecture and integration points: cross-site scripting, cross-site request forgery, XML external entity injection, insufficiently protected credentials, and unsafe reflection all arise from the application's need to parse user input and manage session state securely. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intland over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26516HIGH A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entir | Jun 8, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-26515HIGH An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains t | Jun 8, 2021 | 7.5 | 22 | NO | NO |
CVE-2019-20635MEDIUM codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields. | Apr 2, 2020 | 6.1 | 22 | NO | NO |
CVE-2023-4296MEDIUM If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the ta | Aug 29, 2023 | 6.1 | 20 | NO | NO |
CVE-2020-26513MEDIUM An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely conf | Dec 7, 2020 | 5.5 | 19 | NO | NO |
CVE-2019-19913MEDIUM In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter. | Mar 30, 2020 | 4.8 | 19 | NO | NO |
CVE-2019-19912MEDIUM In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scr | Mar 30, 2020 | 4.8 | 19 | NO | NO |
CVE-2020-26517MEDIUM A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to u | Jun 8, 2021 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intland.
Media articles that mention a CVE ID that affects a product developed by Intland — matched by CVE ID, not by vendor name.