« Back to list

Hcltech

Hcltech Appscan: vulnerabilities and CVEs

Hcltech Appscan has 8 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2019-4326High (7.5)1.1%—Oct 6, 2020
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
CVE-2019-4325Medium (5.3)0.54%—Oct 6, 2020
"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
CVE-2019-4324Medium (6.1)0.65%—Jul 7, 2020
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2019-4323Medium (4.3)0.75%—Jul 7, 2020
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
CVE-2019-4327High (7.5)1.0%—Apr 21, 2020
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
CVE-2019-4393Critical (9.8)1.0%—Apr 7, 2020
HCL AppScan Standard is vulnerable to excessive authorization attempts
CVE-2019-4391High (8.2)1.2%—Apr 7, 2020
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-4392Critical (9.8)1.4%—Feb 14, 2020
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

Other products by Hcltech