First published: Tue Oct 06 2020(Updated: )
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Appscan | <=10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4326 is classified as a medium severity vulnerability due to the potential exposure of sensitive data.
To remediate CVE-2019-4326, ensure that the HTTP Strict-Transport-Security header is implemented in the administration section of the web application console.
CVE-2019-4326 affects HCL AppScan Enterprise versions up to and including 10.0.0.
The impact of CVE-2019-4326 includes the risk of man-in-the-middle attacks due to the lack of a security header.
Yes, CVE-2019-4326 is a web application vulnerability impacting the security of the web application console in HCL AppScan Enterprise.