First published: Tue Apr 21 2020(Updated: )
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL AppScan | <=9.0.3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4327 has a medium severity level due to the potential for unauthorized access to sensitive information.
To mitigate CVE-2019-4327, update HCL AppScan Enterprise to version 9.0.3.15 or later to eliminate the use of hard-coded credentials.
The risks include unauthorized access to the application's encrypted files, which could lead to data breaches.
CVE-2019-4327 affects HCL AppScan Enterprise versions up to and including 9.0.3.14.
Yes, CVE-2019-4327 can be exploited remotely if an attacker has knowledge of the hard-coded credentials.