"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embed the contents of untrusted web pages in a frame."
"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
HCL AppScan Standard is vulnerable to excessive authorization attempts