Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown

CVE-2019-4388

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
Attacker Value
Unknown

CVE-2019-16188

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.
Attacker Value
Unknown

CVE-2015-1952

Disclosure Date: April 16, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.
0
Attacker Value
Unknown

CVE-2014-6120

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.
0
Attacker Value
Unknown

CVE-2016-9981

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257
0
Attacker Value
Unknown

CVE-2016-3034

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
0
Attacker Value
Unknown

CVE-2016-6042

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to execute arbitrary code on the system in the same context as the victim.
0
Attacker Value
Unknown

CVE-2016-3035

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
0
Attacker Value
Unknown

CVE-2016-3033

Disclosure Date: December 01, 2016 (last updated November 25, 2024)
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2016-0288

Disclosure Date: June 01, 2016 (last updated November 25, 2024)
IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0