Skip to main content

Vendor/product archive

ibm / security_appscan CVEs

Beta · best-effort

27 CVEs tagged to ibm / security_appscan1 Critical, 4 High, 18 Medium, 4 Low, 0 Unrated.

CVE-2015-1952

Published Apr 16, 2018

Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9981

Published Aug 2, 2017

IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6042

Published Feb 1, 2017

IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to o…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0288

Published Jun 1, 2016

IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8918

Published Feb 2, 2015

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6136

Published Feb 2, 2015

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4806

Published Aug 29, 2014

The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0904

Published Mar 26, 2014

The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attackers to execute arbitrary code…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5453

Published Nov 13, 2013

IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily pre…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-5450

Published Nov 13, 2013

IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leve…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5430

Published Oct 28, 2013

The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, which makes it easier for remote authenticated users to obtai…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3989

Published Oct 25, 2013

IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive inform…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2997

Published Sep 8, 2013

IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattend…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0531

Published Sep 8, 2013

The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtai…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0513

Published Mar 29, 2013

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the ser…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0511

Published Mar 29, 2013

Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0510

Published Mar 29, 2013

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2