Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-30149

Disclosure Date: October 31, 2024 (last updated October 31, 2024)
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
0
Attacker Value
Unknown

CVE-2019-4388

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
Attacker Value
Unknown

CVE-2019-16188

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.
Attacker Value
Unknown

CVE-2014-6120

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.
0
Attacker Value
Unknown

CVE-2016-3034

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
0
Attacker Value
Unknown

CVE-2016-3035

Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
0
Attacker Value
Unknown

CVE-2016-3033

Disclosure Date: December 01, 2016 (last updated November 25, 2024)
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2014-6123

Disclosure Date: December 29, 2014 (last updated October 05, 2023)
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs.
0
Attacker Value
Unknown

CVE-2014-6135

Disclosure Date: December 23, 2014 (last updated October 05, 2023)
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-6121

Disclosure Date: December 23, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0