Security Appscan Source

Vendor:

First CVE: Jun 20, 2012 · Active for 14 years

14
Total CVEs
More Total CVEs than 91% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Appscan Source over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2012
14 years ago
Most Recent CVE
Apr 12, 2018
3,026 days ago

CVE Severity & Scoring

Security Appscan Source14 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local1 (7.1%)
Network2 (14.3%)
Unknown11 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (21.4%)
High0 (0.0%)
Unknown11 (78.6%)
User Interaction
None3 (21.4%)
Unknown11 (78.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None2 (14.3%)
Unknown11 (78.6%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 al
Apr 12, 20189.831NONO
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.
Dec 23, 20149.329NONO
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
Feb 1, 20175.320NONO
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and
Jun 20, 20125.820NONO
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.
Feb 1, 20174.418NONO
Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, and 9.0 thr
Aug 12, 20147.218NONO
The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote a
Jun 20, 20125.018NONO
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.
Dec 23, 20144.317NONO
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Coll
Jun 20, 20124.317NONO
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.
Dec 23, 20145.516NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Security Appscan Source

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.324.80.6%00
9.0.224.80.6%00
9.0.195.11.6%00
9.0.0.136.32.0%00
9.0.0.026.02.7%00
9.043.90.4%00
8.855.01.4%00
8.7.0.145.21.6%00
8.7.0.033.70.4%00
8.735.32.1%00
8.6.0.245.21.6%00
8.6.0.145.21.6%00
8.6.0.026.02.7%00
8.634.40.5%00
8.5.0.154.81.1%00
8.564.71.1%00
8.0.0.254.81.1%00
8.0.0.154.81.1%00
8.064.71.1%00
7.035.01.6%00