Codebeamer
Vendor:
First CVE: Mar 30, 2020 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Codebeamer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2020
6 years ago
Most Recent CVE
Aug 29, 2023
1,060 days ago
CVE Severity & Scoring
Codebeamer8 CVEs
75%
25%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (12.5%)
Unknown0 (0.0%)
Required7 (87.5%)
Privileges Required
Low0 (0.0%)
High3 (37.5%)
None5 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26516HIGH A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entir | Jun 8, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-26515HIGH An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains t | Jun 8, 2021 | 7.5 | 22 | NO | NO |
CVE-2019-20635MEDIUM codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields. | Apr 2, 2020 | 6.1 | 22 | NO | NO |
CVE-2023-4296MEDIUM If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the ta | Aug 29, 2023 | 6.1 | 20 | NO | NO |
CVE-2020-26513MEDIUM An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely conf | Dec 7, 2020 | 5.5 | 19 | NO | NO |
CVE-2019-19913MEDIUM In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter. | Mar 30, 2020 | 4.8 | 19 | NO | NO |
CVE-2019-19912MEDIUM In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scr | Mar 30, 2020 | 4.8 | 19 | NO | NO |
CVE-2020-26517MEDIUM A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to u | Jun 8, 2021 | 4.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Codebeamer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.5.0 | 1 | 6.1 | 0.9% | 0 | 0 |
| 22.10.0 | 1 | 6.1 | 0.6% | 0 | 0 |
| 22.04.0 | 1 | 6.1 | 0.6% | 0 | 0 |
| 21.09.0 | 1 | 6.1 | 0.6% | 0 | 0 |
| 21.04 | 2 | 6.8 | 0.7% | 0 | 0 |
| 10.1.0 | 4 | 6.7 | 0.7% | 0 | 0 |
| 10.0.1 | 2 | 6.8 | 0.7% | 0 | 0 |
| 10.0.0 | 2 | 6.8 | 0.7% | 0 | 0 |