VendorsHcltechappscanall versions
Vulnerabilities

Hcltech HCL Technologies AppScan Standard Edition

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2019-4392
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
Published 2020-02-14 · Modified
10.0EPSS 0.014
CVE-2019-4393
HCL AppScan Standard is vulnerable to excessive authorization attempts
Published 2020-04-07 · Modified
9.8EPSS 0.010
CVE-2019-4391
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Published 2020-04-07 · Modified
8.2EPSS 0.012
CVE-2019-4326
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Published 2020-10-06 · Modified
7.5EPSS 0.011
CVE-2019-4327
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Published 2020-04-21 · Modified
7.5EPSS 0.010
CVE-2019-4324
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
Published 2020-07-07 · Modified
6.1EPSS 0.006
CVE-2019-4325
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
Published 2020-10-06 · Modified
5.3EPSS 0.005
CVE-2019-4323
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
Published 2020-07-07 · Modified
4.3EPSS 0.008