CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Rational Policy Tester Security AppscanApr 29, 2026 Mar 29, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in the Manual Explore browser plug-in for Firefox in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to...Show more |
Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters. |
IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing t...Show more |
1Ibm 2Rational Policy Tester Security AppscanApr 29, 2026 Mar 29, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication cred...Show more |
1Ibm 2Rational Policy Tester Security AppscanApr 29, 2026 Mar 29, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject arbitrary web scrip...Show more |
1Ibm 2Rational Policy Tester Security AppscanApr 29, 2026 Dec 28, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoo...Show more |
1Ibm 2Rational Policy Tester Security AppscanApr 29, 2026 Dec 28, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary...Show more |