IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_appscan_source | Ibm | 8.0 (including) | 8.0 (including) |
Security_appscan_source | Ibm | 8.5 (including) | 8.5 (including) |
Security_appscan_source | Ibm | 8.6 (including) | 8.6 (including) |
Security_appscan_source | Ibm | 8.7 (including) | 8.7 (including) |
Security_appscan_source | Ibm | 8.8 (including) | 8.8 (including) |
Security_appscan_source | Ibm | 9.0 (including) | 9.0 (including) |