CVE-2019-4327: High severity hcl appscan vulnerability
Published Apr 21, 2020
·Updated
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Affected Software
1 affected component
hcltech Appscan<=9.0.3.14
Event History
Apr 21, 2020
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4327?
CVE-2019-4327 has a medium severity level due to the potential for unauthorized access to sensitive information.
2
How do I fix CVE-2019-4327?
To mitigate CVE-2019-4327, update HCL AppScan Enterprise to version 9.0.3.15 or later to eliminate the use of hard-coded credentials.
3
What are the risks associated with CVE-2019-4327?
The risks include unauthorized access to the application's encrypted files, which could lead to data breaches.
4
Which versions of HCL AppScan Enterprise are affected by CVE-2019-4327?
CVE-2019-4327 affects HCL AppScan Enterprise versions up to and including 9.0.3.14.
5
Can CVE-2019-4327 be exploited remotely?
Yes, CVE-2019-4327 can be exploited remotely if an attacker has knowledge of the hard-coded credentials.