Vulnerabilities > IBM > Security Appscan > 8.6.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-04-16 CVE-2015-1952 Cross-site Scripting vulnerability in IBM Security Appscan
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2014-08-29 CVE-2014-4806 Insufficiently Protected Credentials vulnerability in IBM Security Appscan
The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.
local
low complexity
ibm CWE-522
5.5