An insufficiently protected credentials issue was...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 27, 2023
Description
Published by the National Vulnerability Database
Jun 8, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Oct 27, 2023
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
References