CVE-2019-4326: High severity hcl appscan vulnerability
Published Oct 6, 2020
·Updated
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Affected Software
1 affected component
hcltech Appscan<=10.0.0
Remediation
Event History
Oct 6, 2020
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4326?
CVE-2019-4326 is classified as a medium severity vulnerability due to the potential exposure of sensitive data.
2
How do I fix CVE-2019-4326?
To remediate CVE-2019-4326, ensure that the HTTP Strict-Transport-Security header is implemented in the administration section of the web application console.
3
What does CVE-2019-4326 affect?
CVE-2019-4326 affects HCL AppScan Enterprise versions up to and including 10.0.0.
4
What is the impact of CVE-2019-4326?
The impact of CVE-2019-4326 includes the risk of man-in-the-middle attacks due to the lack of a security header.
5
Is CVE-2019-4326 a web application vulnerability?
Yes, CVE-2019-4326 is a web application vulnerability impacting the security of the web application console in HCL AppScan Enterprise.