PT-2020-16433 · Intland · Codebeamer Alm

Alex Joss

+1

·

Published

2020-12-07

·

Updated

2023-10-18

·

CVE-2020-26513

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Intland codeBeamer ALM versions 10.x through 10.1.SP4
Description An issue was discovered in the way Intland codeBeamer ALM parses ReqIF XML data used for importing projects. The software components are insecurely configured, allowing for XML External Entity Attacks.
Recommendations For versions 10.x through 10.1.SP4, consider disabling the import of ReqIF XML data until a patch is available to prevent potential XML External Entity Attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-26513

Affected Products

Codebeamer Alm