IBM Security AppScan Enterprise 8.5 up to and including 8.7.0.1, when Jazz authentication is enabled, allows man-in-the-middle malicious users to obtain sensitive information or modify data by leveraging an improperly protected URL to obtain a session token.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm security appscan 8.7.0.0 |
||
ibm security appscan 8.7.0.1 |
||
ibm security appscan 8.5.0.0 |
||
ibm security appscan 8.5.0.1 |
||
ibm security appscan 8.6.0.0 |
||
ibm security appscan 8.6.0.1 |
||
ibm security appscan 8.6.0.2 |