← Back

Appscan Source

appscan_source

Vendor: Hcltech • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hcltech
1Appscan Source
Jun 17, 2026
Oct 31, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
1Hcltech
1Appscan Source
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
1Hcltech
1Appscan Source
Jun 17, 2026
Sep 25, 2019
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to...Show more
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.Show less