Vulnerabilities > IBM > Security Appscan Source > 7.0

DATE CVE VULNERABILITY TITLE RISK
2012-06-20 CVE-2012-2173 Credentials Management vulnerability in IBM Security Appscan Source
The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
ibm CWE-255
5.0
2012-06-20 CVE-2012-2161 Cross-Site Scripting vulnerability in IBM Security Appscan Source and Spss Data Collection
Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
ibm CWE-79
4.3
2012-06-20 CVE-2012-2159 Improper Input Validation vulnerability in IBM Security Appscan Source and Spss Data Collection
Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
ibm CWE-20
5.8