cbcvebase.

Ibm Security Appscan vulnerabilities

27 known vulnerabilities affecting ibm/security_appscan.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM18LOW4

Vulnerabilities

Page 2 of 2
CVE-2013-0473P4MEDIUMCVSS 4.3v5.6.0.0v8.0.0.0+10 more2013-03-29
CVE-2013-0473 [MEDIUM] CWE-79 CVE-2013-0473: Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x b Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject arbitrary web script or HTML via a crafted report.
nvd
CVE-2013-5453P4LOWCVSS 3.5v5.6.0.0v6.0.0.0+16 more2013-11-13
CVE-2013-5453 [LOW] CWE-200 CVE-2013-5453: IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitr IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
nvd
CVE-2013-0510P4MEDIUMCVSS 4.3v5.6.0.0v8.0.0.0+10 more2013-03-29
CVE-2013-0510 [MEDIUM] CWE-264 CVE-2013-0510: IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session c IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.
nvd
CVE-2013-5450P4MEDIUMCVSS 4.0v8.5.0.0v8.5.0.1+5 more2013-11-13
CVE-2013-5450 [MEDIUM] CWE-255 CVE-2013-5450: IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man IBM Security AppScan Enterprise 8.5 through 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle attackers to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
nvd
CVE-2014-6121P4LOWCVSS 3.5v8.5v8.6+4 more2014-12-23
CVE-2014-6121 [LOW] CWE-79 CVE-2014-6121: Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, Cross-site scripting (XSS) vulnerability in IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-3989P4LOWCVSS 3.5v8.0.0.0v8.0.0.1+11 more2013-10-25
CVE-2013-3989 [LOW] CWE-310 CVE-2013-3989: IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.
nvd
CVE-2013-2997P4LOWCVSS 1.7≤ 8.6.0.2v5.6.0.0+14 more2013-09-08
CVE-2013-2997 [LOW] CWE-264 CVE-2013-2997: IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout act IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
nvd
Ibm Security Appscan vulnerabilities | cvebase