CVE-2014-0936: IBM Security Appscan Source
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
IBM Security AppScan Source 8.0 through 9.0, when the publish-assessment permission is not properly restricted for the configured database server, transmits cleartext assessment data, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected products
- IBM Security Appscan Source: version 8.0 only; version 8.5 only; version 8.6 only; version 8.7 only; version 8.8 only; version 9.0 only
Published 2014-06-08. Last modified 2026-06-17.