CVE-2014-6136

IBM Security AppScan Standard 8.x-9.x - Unencrypted Session Information Disclosure

Title source: llm
STIX 2.1

Description

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21695170
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96816

Scores

EPSS 0.0117
EPSS Percentile 64.2%

Details

CWE
CWE-310
Status published
Products (15)
ibm/security_appscan 8.0.0.0
ibm/security_appscan 8.0.0.1
ibm/security_appscan 8.0.0.2
ibm/security_appscan 8.0.0.3
ibm/security_appscan 8.5.0.0
ibm/security_appscan 8.5.0.1
ibm/security_appscan 8.6.0.0
ibm/security_appscan 8.6.0.1
ibm/security_appscan 8.7.0.0
ibm/security_appscan 8.7.0.1
... and 5 more
Published Feb 02, 2015
Tracked Since Feb 18, 2026