CVE-2020-26515: High severity ptc codebeamer vulnerability
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CBLOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26515?
CVE-2020-26515 is considered a critical vulnerability due to its impact on exposed user credentials.
How do I fix CVE-2020-26515?
To fix CVE-2020-26515, upgrade Intland codeBeamer ALM to version 10.1.0.SP5 or later.
What types of issues does CVE-2020-26515 expose?
CVE-2020-26515 exposes encrypted user credentials through an insecure remember-me cookie.
Which versions of Intland codeBeamer are affected by CVE-2020-26515?
CVE-2020-26515 affects Intland codeBeamer ALM versions 10.0.0 to 10.1.0.SP4.
Is CVE-2020-26515 related to cookie security?
Yes, CVE-2020-26515 relates directly to insufficient protection of user credentials stored in a remember-me cookie.