CVE-2019-20635: Medium severity ptc codebeamer vulnerability
Published Apr 2, 2020
·Updated
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
Affected Software
2 affected components
Intland codeBeamer<=9.4.0
Intland codeBeamer=9.5.0-rc2
Event History
Apr 2, 2020
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20635?
CVE-2019-20635 is rated as a high severity vulnerability due to its potential to allow unauthorized execution of Java code.
2
How do I fix CVE-2019-20635?
To fix CVE-2019-20635, upgrade to codeBeamer version 9.5.0-RC3 or later.
3
What versions of codeBeamer are affected by CVE-2019-20635?
CVE-2019-20635 affects codeBeamer versions earlier than 9.5.0-RC3, including all versions up to 9.4.0 and 9.5.0-RC2.
4
What kind of access does CVE-2019-20635 exploit?
CVE-2019-20635 allows exploitation through improper restriction of executing custom Java code and accessing the Java class loader.
5
Is there a workaround for CVE-2019-20635 until I can update?
There are no specific workarounds for CVE-2019-20635, making it essential to upgrade the affected software as soon as possible.