Vulnerabilities (CVE)

Filtered by vendor Hcltech Subscribe
Filtered by product Appscan
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-4326 1 Hcltech 1 Appscan 2020-10-19 5.0 MEDIUM 7.5 HIGH
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
CVE-2019-4327 1 Hcltech 1 Appscan 2020-04-29 5.0 MEDIUM 7.5 HIGH
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
CVE-2019-4391 1 Hcltech 1 Appscan 2020-04-08 6.4 MEDIUM 8.2 HIGH
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data