Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm security appscan 8.7.0.0 vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2013-5450
IBM Security AppScan Enterprise 8.5 up to and including 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle malicious users to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.5.0.1
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.6.0.1
Ibm Security Appscan 8.6.0.2
312
VMScore
CVE-2015-1952
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x prior to 9.0.2 iFix 001 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 9.0.0.0
Ibm Security Appscan 9.0.1.0
Ibm Security Appscan 9.0.2.0
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.8.0.0
356
VMScore
CVE-2016-0288
IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x prior to 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML E...
Ibm Security Appscan 9.0.1.1
Ibm Security Appscan 9.0.0.1
Ibm Security Appscan 9.0.3.1
Ibm Security Appscan 9.0.0.0
Ibm Security Appscan 8.8.0.0
Ibm Security Appscan 9.0.3.0
Ibm Security Appscan 9.0.2.1
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 9.0.2.0
Ibm Security Appscan 9.0.1.0
312
VMScore
CVE-2013-3989
IBM Security AppScan Enterprise 8.x prior to 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.
Ibm Security Appscan 8.0.0.0
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.6.0.1
Ibm Security Appscan 8.0.1.0
Ibm Security Appscan 8.0.1.1
Ibm Security Appscan 8.0.11
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 8.0.0.1
Ibm Security Appscan 8.0.0.2
Ibm Security Appscan 8.6.0.2
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.5.0.1
490
VMScore
CVE-2013-5430
The Jazz Team Server component in IBM Security AppScan Enterprise 8.x prior to 8.8 has a default username and password, which makes it easier for remote authenticated users to obtain unspecified access to this component by leveraging this credential information in an environment ...
Ibm Security Appscan 8.0.0.2
Ibm Security Appscan 8.0.1.0
Ibm Security Appscan 8.6.0.2
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.5.0.1
Ibm Security Appscan 8.0.1.1
Ibm Security Appscan 8.0.11
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 8.0.0.0
Ibm Security Appscan 8.0.0.1
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.6.0.1
445
VMScore
CVE-2014-6136
IBM Security AppScan Standard 8.x and 9.x prior to 9.0.1.1 FP1 supports unencrypted sessions, which allows remote malicious users to obtain sensitive information by sniffing the network.
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.5.0.1
Ibm Security Appscan 8.0.0.2
Ibm Security Appscan 8.0.0.3
Ibm Security Appscan 8.8.0.0
Ibm Security Appscan 9.0.0.0
Ibm Security Appscan 8.0.0.0
Ibm Security Appscan 8.0.0.1
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 9.0.0.1
Ibm Security Appscan 9.0.1.0
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.6.0.1
Ibm Security Appscan 9.0.1.1
516
VMScore
CVE-2014-8918
IBM Security AppScan Standard 8.x and 9.x prior to 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a crafted certificate.
Ibm Security Appscan 8.0.0.1
Ibm Security Appscan 8.0.0.2
Ibm Security Appscan 8.8.0.0
Ibm Security Appscan 9.0.0.0
Ibm Security Appscan 8.0.0.3
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 9.0.0.1
Ibm Security Appscan 9.0.1.0
Ibm Security Appscan 8.0.0.0
Ibm Security Appscan 8.6.0.1
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 8.5.0.1
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 9.0.1.1
312
VMScore
CVE-2013-5453
IBM Security AppScan Enterprise 5.6 up to and including 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
Ibm Security Appscan 6.0.2.0
Ibm Security Appscan 6.0.0.0
Ibm Security Appscan 6.0.1.0
Ibm Security Appscan 8.0.1.1
Ibm Security Appscan 8.0.11
Ibm Security Appscan 8.7.0.1
Ibm Security Appscan 5.6.0.0
Ibm Security Appscan 8.0.0.2
Ibm Security Appscan 8.0.1.0
Ibm Security Appscan 8.6.0.2
Ibm Security Appscan 8.7.0.0
Ibm Security Appscan 6.1.1.0
Ibm Security Appscan 8.5.0.0
Ibm Security Appscan 8.5.0.1
Ibm Security Appscan 8.0.0.0
Ibm Security Appscan 8.0.0.1
Ibm Security Appscan 8.6.0.0
Ibm Security Appscan 8.6.0.1
641
VMScore
CVE-2014-3072
Unspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 up to and including 8.0.0.2, 8.5 up to and including 8.5.0.1, 8.6 up to and including 8.6.0.2, 8.7 up to and including 8.7.0.1, 8.8, and 9.0 up to and including 9.0.0.1 allows local users to gain ...
Ibm Security Appscan Source 8.6.0.2
Ibm Security Appscan Source 8.6.0.1
Ibm Security Appscan Source 8.0.0.1
Ibm Security Appscan Source 8.0.0.2
Ibm Security Appscan Source 9.0.0.1
Ibm Security Appscan Source 8.6
Ibm Security Appscan Source 8.0
Ibm Security Appscan Source 8.8
Ibm Security Appscan Source 9.0
Ibm Security Appscan Source 8.7.0.0
Ibm Security Appscan Source 8.7.0.1
Ibm Security Appscan Source 8.5
Ibm Security Appscan Source 8.5.0.1
160
VMScore
CVE-2014-4812
The installer in IBM Security AppScan Source 8.x and 9.x up to and including 9.0.1 has an open network port for a debug service, which allows remote malicious users to obtain sensitive information by connecting to this port.
Ibm Security Appscan Source 8.5.0.1
Ibm Security Appscan Source 8.6
Ibm Security Appscan Source 8.6.0.1
Ibm Security Appscan Source 9.0.0.1
Ibm Security Appscan Source 9.0.1
Ibm Security Appscan Source 8.0.0.2
Ibm Security Appscan Source 8.5
Ibm Security Appscan Source 8.8
Ibm Security Appscan Source 9.0
Ibm Security Appscan Source 8.6.0.2
Ibm Security Appscan Source 8.7
Ibm Security Appscan Source 8.0
Ibm Security Appscan Source 8.0.0.1
Ibm Security Appscan Source 8.7.0.0
Ibm Security Appscan Source 8.7.0.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »