Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2013-5453
Disclosure Date: November 13, 2013 (last updated October 05, 2023)
IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
0
Attacker Value
Unknown
CVE-2013-0531
Disclosure Date: September 08, 2013 (last updated October 05, 2023)
The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
0
Attacker Value
Unknown
CVE-2013-2997
Disclosure Date: September 08, 2013 (last updated October 05, 2023)
IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
0
Attacker Value
Unknown
CVE-2012-0738
Disclosure Date: December 28, 2012 (last updated October 05, 2023)
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
0
Attacker Value
Unknown
CVE-2012-0741
Disclosure Date: December 28, 2012 (last updated October 05, 2023)
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
0