First published: Tue Jun 08 2021(Updated: )
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intland codeBeamer | >=10.0.0<10.1.0 | |
Intland codeBeamer | =10.1.0 | |
Intland codeBeamer | =10.1.0-sp1 | |
Intland codeBeamer | =10.1.0-sp2 | |
Intland codeBeamer | =10.1.0-sp3 | |
Intland codeBeamer | =10.1.0-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.