Vulnerabilities > CVE-2019-4391 - XXE vulnerability in Hcltech Appscan 9.0.3.13/9.0.3.14

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
hcltech
CWE-611

Summary

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

Vulnerable Configurations

Part Description Count
Application
Hcltech
3