Vulnerability Description
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intland | Codebeamer | 10.0.0 |
Related Weaknesses (CWE)
References
- https://intland.com/codebeamer/application-lifecycle-management/Vendor Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-08_CSNC-2020ExploitThird Party Advisory
- https://intland.com/codebeamer/application-lifecycle-management/Vendor Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-08_CSNC-2020ExploitThird Party Advisory
FAQ
What is CVE-2020-26516?
CVE-2020-26516 is a vulnerability with a CVSS score of 8.8 (HIGH). A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowi...
How severe is CVE-2020-26516?
CVE-2020-26516 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26516?
Check the references section above for vendor advisories and patch information. Affected products include: Intland Codebeamer.