Security Appscan Source
Vendor:
First CVE: Jun 20, 2012 · Active for 14 years
14
Total CVEs
More Total CVEs than 91% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Appscan Source over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2012
14 years ago
Most Recent CVE
Apr 12, 2018
3,026 days ago
CVE Severity & Scoring
Security Appscan Source14 CVEs
21%
57%
14%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (7.1%)
Network2 (14.3%)
Unknown11 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (21.4%)
High0 (0.0%)
Unknown11 (78.6%)
User Interaction
None3 (21.4%)
Unknown11 (78.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None2 (14.3%)
Unknown11 (78.6%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6120CRITICAL IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 al | Apr 12, 2018 | 9.8 | 31 | NO | NO |
CVE-2014-6119HIGH IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9. | Dec 23, 2014 | 9.3 | 29 | NO | NO |
CVE-2016-3035MEDIUM IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. | Feb 1, 2017 | 5.3 | 20 | NO | NO |
CVE-2012-2159MEDIUM Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and | Jun 20, 2012 | 5.8 | 20 | NO | NO |
CVE-2016-3034MEDIUM IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily. | Feb 1, 2017 | 4.4 | 18 | NO | NO |
CVE-2014-3072HIGH Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, and 9.0 thr | Aug 12, 2014 | 7.2 | 18 | NO | NO |
CVE-2012-2173MEDIUM The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote a | Jun 20, 2012 | 5.0 | 18 | NO | NO |
CVE-2014-6135MEDIUM IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9. | Dec 23, 2014 | 4.3 | 17 | NO | NO |
CVE-2012-2161MEDIUM Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Coll | Jun 20, 2012 | 4.3 | 17 | NO | NO |
CVE-2014-6122MEDIUM IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9. | Dec 23, 2014 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Security Appscan Source
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.3 | 2 | 4.8 | 0.6% | 0 | 0 |
| 9.0.2 | 2 | 4.8 | 0.6% | 0 | 0 |
| 9.0.1 | 9 | 5.1 | 1.6% | 0 | 0 |
| 9.0.0.1 | 3 | 6.3 | 2.0% | 0 | 0 |
| 9.0.0.0 | 2 | 6.0 | 2.7% | 0 | 0 |
| 9.0 | 4 | 3.9 | 0.4% | 0 | 0 |
| 8.8 | 5 | 5.0 | 1.4% | 0 | 0 |
| 8.7.0.1 | 4 | 5.2 | 1.6% | 0 | 0 |
| 8.7.0.0 | 3 | 3.7 | 0.4% | 0 | 0 |
| 8.7 | 3 | 5.3 | 2.1% | 0 | 0 |
| 8.6.0.2 | 4 | 5.2 | 1.6% | 0 | 0 |
| 8.6.0.1 | 4 | 5.2 | 1.6% | 0 | 0 |
| 8.6.0.0 | 2 | 6.0 | 2.7% | 0 | 0 |
| 8.6 | 3 | 4.4 | 0.5% | 0 | 0 |
| 8.5.0.1 | 5 | 4.8 | 1.1% | 0 | 0 |
| 8.5 | 6 | 4.7 | 1.1% | 0 | 0 |
| 8.0.0.2 | 5 | 4.8 | 1.1% | 0 | 0 |
| 8.0.0.1 | 5 | 4.8 | 1.1% | 0 | 0 |
| 8.0 | 6 | 4.7 | 1.1% | 0 | 0 |
| 7.0 | 3 | 5.0 | 1.6% | 0 | 0 |