Show filters
65 Total Results
Displaying 1-10 of 65
Sort by:
Attacker Value
Unknown

CVE-2024-30149

Disclosure Date: October 31, 2024 (last updated October 31, 2024)
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
0
Attacker Value
Unknown

CVE-2023-37537

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.
Attacker Value
Unknown

CVE-2019-4325

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
Attacker Value
Unknown

CVE-2019-4326

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Attacker Value
Unknown

CVE-2019-4324

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Attacker Value
Unknown

CVE-2019-4323

Disclosure Date: July 07, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
Attacker Value
Unknown

CVE-2019-4327

Disclosure Date: April 21, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Attacker Value
Unknown

CVE-2019-4391

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Attacker Value
Unknown

CVE-2019-4393

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
HCL AppScan Standard is vulnerable to excessive authorization attempts
Attacker Value
Unknown

CVE-2019-4392

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.