VYPR
High severity7.5NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026

CVE-2020-26515

CVE-2020-26515

Description

An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:intland:codebeamer:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:intland:codebeamer:*:*:*:*:*:*:*:*range: >=10.0.0,<10.1.0
    • cpe:2.3:a:intland:codebeamer:10.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:intland:codebeamer:10.1.0:sp4:*:*:*:*:*:*
  • Intland/codeBeamer ALMcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 10.x through 10.1.SP4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.