Codebeamer
This hub aggregates every CVE we track for Codebeamer, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting Codebeamer.
- CVE-2024-3951Cross-site Scripting in PTC Codebeamer7.1
- CVE-2023-4296PTC Codebeamer Cross site scripting8.8
- CVE-2020-26515An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user...7.5
- CVE-2020-26517A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a ...4.8
- CVE-2020-26516A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted all...8.8
- CVE-2020-26513An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software c...5.5
- CVE-2019-20635codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.6.1
- CVE-2019-19912In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an activ...4.8
- CVE-2019-19913In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.4.8
Product normalization is registry-driven with AI assist and human review. How it works