IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6136
Reference (s):
- http://www-01.ibm.com/support/docview.wss?uid=swg21695170
- XF:ibm-appscan-cve20146136-info-disc(96816)
- URL: https://exchange.xforce.ibmcloud.com/vulnerabilities/96816

