Appscan

Vendor:

First CVE: Feb 14, 2020 · Active for 6 years

8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Appscan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2020
6 years ago
Most Recent CVE
Oct 6, 2020
2,117 days ago

CVE Severity & Scoring

Appscan8 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HCL AppScan Standard is vulnerable to excessive authorization attempts
Apr 7, 20209.829NONO
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
Feb 14, 20209.829NONO
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Oct 6, 20207.525NONO
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Apr 7, 20208.225NONO
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Apr 21, 20207.523NONO
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Jul 7, 20206.122NONO
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
Oct 6, 20205.320NONO
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
Jul 7, 20204.318NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Appscan

Top CWEs

Versions

No cataloged versions.