Polarion Alm Siemens Polarion Alm

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Siemens Polarion Alm.

By the Year

In 2026 there have been 0 vulnerabilities in Siemens Polarion Alm. Polarion Alm did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 2 8.80
2023 1 5.90
2022 2 5.75

It may take a day or so for new Polarion Alm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Siemens Polarion Alm Security Vulnerabilities

Polarion ALM REST API doorsconnector Auth Bypass <v2404.0
CVE-2024-23813 9.8 - Critical - February 13, 2024

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potentially execute code.

authentification

Polarion ALM <V2404.0 Weak Permissions PrivEsc NT AUTHORITY SYSTEM
CVE-2023-50236 7.8 - High - February 13, 2024

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in the installation path. An attacker with local access could exploit this vulnerability to escalate privileges to NT AUTHORITY\SYSTEM.

Incorrect Default Permissions

Polarion ALM XXE Leading to File Disclosure
CVE-2023-28828 5.9 - Medium - April 11, 2023

A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

XXE

Polarion ALM Host Header Injection (<V2304.0) allows spoofing
CVE-2022-46265 5.4 - Medium - December 13, 2022

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability that could allow an attacker to spoof a Host header information and redirect users to malicious websites.

Injection

A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions)
CVE-2021-44478 6.1 - Medium - March 08, 2022

A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary code and extract sensitive information by sending a specially crafted link to users with administrator privileges.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Siemens Polarion Alm or by Siemens? Click the Watch button to subscribe.

Siemens
Vendor

subscribe