What's new in HCL AppScan® Enterprise
This section describes new AppScan Enterprise product features and enhancements in this release, as well as deprecations and anticipated changes, where relevant.
New in HCL AppScan® Enterprise
Note:
Versions 10.6.0 and
earlier reached end of support, so we removed them from the documentation.
New in HCL AppScan® Enterprise 10.12.0
- Scan-level attributes in reports: Exported security reports now include scan-level attributes, such as Scan Type, Test Optimization Level, and Test Policy, helping you easily track configuration changes over time.
- Advanced risk data import: AppScan Enterprise is now compatible with importing issue files from AppScan on Cloud containing CVSS 4.0 metrics.
- Enriched compliance reporting: You can now view CVSS 4.0 vectors directly within Industry Standard and Regulatory Compliance reports (such as ISO 27001, NIST SP 800-53, PCI DSS, and GDPR).
- Updated industry standard reports: The CWE Top 25 Most Dangerous Software Weaknesses report has been upgraded to the 2025 edition, and the OWASP Application Security Verification Standard report has been upgraded to version 5.0.
- Agent host modernization: The Dynamic Analysis Scanner AgentHost has been migrated to .NET 8 to support modern engine features and improve performance. You can deploy the agent using a new standalone installer, which is separate from the main AppScan Enterprise Server installer. Note:Installing the .NET 8 agent and AppScan Enterprise Server on a single host is unsupported.
- System and platform support: Official support has been added for Microsoft SQL Server 2025.
- Database driver support: Support for the Microsoft OLE DB Driver 19 has been added, which enforces encrypted database connections and sets Trust Server Certificate to true by default.
Important:
AppScan Enterprise doesn't support the
CAPTCHA-based login templates from AppScan Standard. If you attempt to upload an
AppScan Standard template (
.scant) file where CAPTCHA login is
enabled, the system blocks the upload and displays a validation error.IAST agent updates
The IAST agents have been upgraded to the
following versions:
- Java: 1.23.2
- .NET: 1.17.2
- Node.js: 1.15.3
- PHP: 1.3.0
APAR fix list
The following Authorized Program Analysis Reports (APARs) and tracked issues were fixed:
| APAR No. | Description |
|---|---|
| KB0119106 | Fixed an issue where multiple issue IDs were displayed with the same test URL for a specific issue type. |
| KB0128678 | Resolved an issue where the POST/jobs API failed for DAST configurations containing a traffic file. |
| KB0129287 | Fixed an issue that caused scans to suspend during post-processing for the "Application Patch Overflow" issue type. |
| KB0129941 | Resolved a connection failure in the Configuration Wizard when connecting to a SQL Server using a specific driver. |
| KB0130646 | Fixed an error that occurred when adding comments to an issue due to differing character set encodings. |
| KB0131058 | Resolved an issue where the Issues API v2 failed for non-English user locales. |
| KB0131077 | Fixed an issue causing scans to suspend during post-processing due to a "malformed string" error. |
| KB0131203 | Resolved an issue where duplicate issues were created for identical vulnerabilities during HCL AppScan Standard imports. |
| KB0131221 | Fixed an error that caused PDF report generation to fail in the Scans view. |
Fixes and security updates
New security rules have been added to detect the following vulnerabilities:
attCrawl4AIRCECVE202626216- Crawl4AI RCE CVE-2026-26216JsfWeakSecretKey- JavaServer Faces (JSF) Weak Secret KeyYii2WeakSecretKey- Yii2 Weak Cookie Validation KeyPeopleSoftWeakSecretKey- Oracle PeopleSoft Weak Secret KeyattLangflowRCECVE20253248- Langflow RCE CVE-2025-3248attpac4jjwtauthenticatorCVE202629000- pac4j JWT authentication bypass vulnerability CVE-2026-29000attLangflowRCECVE202534291- Langflow RCE CVE-2025-34291attZohoManageEnginePasswordRCECVE202235405- Zoho ManageEngine Multiple Products Remote Code ExecutionattLangflowAuthenticationBypassCVE202621445- Langflow Authentication Bypass CVE-2026-21445- The Vulnerable Component Database has been updated to version 1.11.
This release's complete list of fixes, updates, and RFEs is listed here.
Changed in this release
- The Chromium browser engine has been upgraded to version 149.0.7827.114 to incorporate the latest security fixes.
- WebSphere Application Server Liberty Core has been upgraded to version 26.0.0.4, and the Java Runtime Environment has been updated to IBM Semeru 17.0.19+10.
Removed in this release
- The "Vital Few" and "Developer Essentials" test policies have been removed from AppScan Enterprise. Active scan profiles using these policies are automatically reverted to an unassigned state.
Upcoming changes
- End of Support (EOS): AppScan Enterprise version 10.7.0 will reach EOS on March 31, 2027. As of June 30, 2026, version 10.7.0 is no longer available for download from My HCLSoftware (MHS). Upgrade to the latest available version. Contact Support for assistance. For more information, refer to the announcement blog post.
- Support for the legacy SQLOLEDB database driver will be removed in version 10.13.0. Plan a migration to modern drivers, such as MSOLEDBSQL 18 or 19.
- Support for GPT 4.x models will be dropped as Azure OpenAI is retiring the model.