Filtered by vendor Siemens Subscriptions
Filtered by product Polarion Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-13935 1 Siemens 1 Polarion 2024-09-17 3.5 Low
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.
CVE-2019-13934 1 Siemens 1 Polarion 2024-09-17 3.5 Low
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.
CVE-2019-13936 1 Siemens 1 Polarion 2024-09-16 3.5 Low
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.
CVE-2024-33647 1 Siemens 1 Polarion 2024-08-02 6.5 Medium
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.