IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_appscan_source | Ibm | 8.0 | 8.0 |
Security_appscan_source | Ibm | 8.5 | 8.5 |
Security_appscan_source | Ibm | 8.6 | 8.6 |
Security_appscan_source | Ibm | 8.7 | 8.7 |
Security_appscan_source | Ibm | 8.8 | 8.8 |
Security_appscan_source | Ibm | 9.0 | 9.0 |