CVE-2019-13935: Siemens Polarion

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Affected products

  • Siemens Polarion: before 19.2 (fixed in 19.2)

Published 2019-11-27. Last modified 2026-06-17.