Vulnerabilities > Intland > Codebeamer > 9.0.0

DATE CVE VULNERABILITY TITLE RISK
2020-04-02 CVE-2019-20635 Unsafe Reflection vulnerability in Intland Codebeamer
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
network
intland CWE-470
4.3
2020-03-30 CVE-2019-19913 Cross-site Scripting vulnerability in Intland Codebeamer
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
network
low complexity
intland CWE-79
4.8
2020-03-30 CVE-2019-19912 Cross-site Scripting vulnerability in Intland Codebeamer
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.
network
low complexity
intland CWE-79
4.8