CVE-2014-6136: IBM Security Appscan

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected products

  • IBM Security Appscan: version 8.0.0.0 only; version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.5.0.0 only; version 8.5.0.1 only; …

Published 2015-02-02. Last modified 2026-06-17.