Web Application Console Vulnerability in HCL AppScan Enterprise
CVE-2019-4326
7.5HIGH
What is CVE-2019-4326?
The web application console of HCL AppScan Enterprise is susceptible to security risks due to the absence of the HTTP Strict-Transport-Security (HSTS) header in its administration section. This vulnerability may expose user data and interactions to potential attacks, as the lack of HSTS can permit man-in-the-middle attacks, undermining the application's overall security posture. It is crucial for users of HCL AppScan Enterprise to implement necessary security measures to safeguard their web applications.
Affected Version(s)
"HCL AppScan Enterprise " "10.0.0 and below"