Appscan
Vendor:
First CVE: Feb 14, 2020 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Appscan over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2020
6 years ago
Most Recent CVE
Oct 6, 2020
2,117 days ago
CVE Severity & Scoring
Appscan8 CVEs
38%
38%
25%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-4393CRITICAL HCL AppScan Standard is vulnerable to excessive authorization attempts | Apr 7, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-4392CRITICAL HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | Feb 14, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-4326HIGH "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | Oct 6, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-4391HIGH HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data | Apr 7, 2020 | 8.2 | 25 | NO | NO |
CVE-2019-4327HIGH "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files." | Apr 21, 2020 | 7.5 | 23 | NO | NO |
CVE-2019-4324MEDIUM "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." | Jul 7, 2020 | 6.1 | 22 | NO | NO |
CVE-2019-4325MEDIUM "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." | Oct 6, 2020 | 5.3 | 20 | NO | NO |
CVE-2019-4323MEDIUM "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame." | Jul 7, 2020 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Appscan
Top CWEs
Versions
No cataloged versions.