Vulnerabilities > IBM > Security Appscan > 6.0.1.0

DATE CVE VULNERABILITY TITLE RISK
2013-11-13 CVE-2013-5453 Information Exposure vulnerability in IBM Security Appscan
IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
network
ibm CWE-200
3.5
2013-09-08 CVE-2013-2997 Permissions, Privileges, and Access Controls vulnerability in IBM Security Appscan
IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
local
low complexity
ibm CWE-264
1.7
2013-09-08 CVE-2013-0531 Cryptographic Issues vulnerability in IBM Security Appscan
The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
ibm CWE-310
5.0
2012-12-28 CVE-2012-0741 Improper Input Validation vulnerability in IBM Rational Policy Tester and Security Appscan
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
network
ibm CWE-20
5.8
2012-12-28 CVE-2012-0738 Improper Input Validation vulnerability in IBM Rational Policy Tester and Security Appscan
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.
network
ibm CWE-20
5.8