Appscan
by HCLTech
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-4393 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2020 | HCL AppScan Standard is vulnerable to excessive authorization attempts | ||
| CVE-2019-4392 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | ||
| CVE-2019-4391 | Hig | 0.53 | 8.2 | 0.01 | Apr 7, 2020 | HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data | ||
| CVE-2019-4326 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | ||
| CVE-2019-4327 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2020 | "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | ||
| CVE-2019-4324 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." | ||
| CVE-2019-4325 | Med | 0.34 | 5.3 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." | ||
| CVE-2019-4323 | Med | 0.28 | 4.3 | 0.01 | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." |
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard is vulnerable to excessive authorization attempts
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
- risk 0.53cvss 8.2epss 0.01
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
- risk 0.40cvss 6.1epss 0.01
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
- risk 0.34cvss 5.3epss 0.01
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
- risk 0.28cvss 4.3epss 0.01
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."