← Back to home
ICSA-23-241-01  ·  Published 2023-08-29  ·  View on CISA ICS-CERT ↗

PTC Codebeamer

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to inject arbitrary code into the target's browser.

CVEs (1)

Remediations

  • PTC recommends the following:
  • Codebeamer 22.10.X: upgrade to 22.10-SP7 or newer version
  • Codebeamer 22.04.X: upgrade to 22.04-SP3 or newer version
  • Codebeamer 21.09.X: upgrade to 21.09-SP14 or newer version
  • Docker Image download: https://hub.docker.com/r/intland/codebeamer/tags
  • Codebeamer installers: https://intland.com/codebeamer-download/
  • Hosted customers may request an upgrade through the support channel. Note that version 2.0 is not impacted by this vulnerability.
  • For more information refer to PTC Security Advisory and Resolution.

Affected Vendors

PTC

Affected Products (3)

PTC · Codebeamer 22.10.X <= 22.10-SP6
PTC · Codebeamer 22.04.X <= 22.04-SP2
PTC · Codebeamer 21.09.X <= 21.09-SP13

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more