Skip to main content
TrustRadius
HCL AppScan

HCL AppScan
Formerly from IBM

Overview

What is HCL AppScan?

AppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.

Read more

Learn from top reviewers

Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is HCL AppScan?

AppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.hcl…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

108 people also want pricing

Alternatives Pricing

What is SonarQube?

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

What is Indusface WAS?

Indusface Web Application Scanner provides an application security audit to detect a range of high-risk Vulnerabilities, Malware, and Critical CVEs.

Return to navigation

Product Demos

HCL AppScan: Issue Management Gateway Workflow Overview

YouTube

HCL AppScan: Issue Management Gateway Workflow Overview

YouTube

HCL AppScan Source V10: Scan a GoLang Application

YouTube

Bring Code to Scan into AppScan Source

YouTube

HCL AppScan Standard: Setting Up Your First Scan (v 10.0.0)

YouTube

Setting up HCL License Server for AppScan

YouTube
Return to navigation

Product Details

What is HCL AppScan?

HCL AppScan gives developers, DevOps and security teams a suite of testing tools to find and fix vulnerabilities in applications at all phases of development. It integrates with DevSecOps pipelines to ensure continuous security and compliance.

HCL AppScan Screenshots

Screenshot of Cloud Security: AppScan will scan Docker containers and container images to ensure that third party components have not introduced vulnerabilities to an application. Software composition analysis (SCA) tools help organizations inventory third-party commercial and open source components used within their software to understand which components and versions are being used and to identify security vulnerabilities affecting those components.Screenshot of API Testing: This dangerous attack vector can be secured by identifying vulnerable third-party components, automating and integrating API testing and detecting issues in the IDE.Screenshot of Auto Issue Correlation: AppScan leverages three technologies (DAST, SAST, IAST) to enrich results, validate fixes and reduce the number remediation tasks by grouping issues together.Screenshot of 30+ Code Languages Supported: With over 20 years of experience, HCL AppScan offers an extensive list of supported code languages.

HCL AppScan Video

Discover HCL AppScan’s application security testing solutions in this video. Organizations, from small businesses to large enterprises, can use HCL AppScan to secure web applications and APIs, preventing data breaches with top-tier application security tools.

HCL AppScan Competitors

HCL AppScan Technical Details

Deployment TypesOn-premise, Software as a Service (SaaS), Cloud, or Web-Based
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo
Supported CountriesGlobal

Frequently Asked Questions

AppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.

Veracode, Checkmarx, and Coverity Static Analysis (SAST) are common alternatives for HCL AppScan.

The most common users of HCL AppScan are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(23)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

HCL AppScan has been highly regarded by organizations seeking to secure their mobile and web applications. Users have found the tool invaluable for performing Dynamic Application Scans, enabling them to navigate through sites and identify potential vulnerabilities or fixes. The application offers a range of configurations, allowing users to customize their security measures based on their specific needs and capacity. This flexibility has made HCL AppScan a popular choice for conducting in-depth security assessments as part of vulnerability management programs. Users have compared HCL AppScan with other products and free alternatives, noting that the test patterns have become standardized across different solutions. The tool has not only helped teams reduce errors but also ensured adherence to security best practices throughout the software development cycle. Additionally, HCL AppScan provides holistic visibility into the security posture of applications, safeguarding them from threats, vulnerabilities, and compliance violations. Supporting a wide array of languages, this well-engineered source code analysis tool is highly regarded for its static application security testing capabilities. Users have found it easy to share reports generated by HCL AppScan with development members, facilitating collaboration and problem-solving. Furthermore, the tool has been used to pinpoint application vulnerabilities in web applications as well as ensure patching compliance and identify new vulnerabilities. Overall, HCL AppScan has emerged as a reliable solution for organizations looking to proactively address security concerns within their applications.

Users have made the following recommendations based on their experiences with HCL AppScan:

  1. Use IBM AppScan for comprehensive security testing. It provides a wide range of security testing capabilities, including SAST, DAST, Mobile app Security Testing, and IAST. IBM AppScan is suitable for mobile-based organizations and offers support for multiple programming languages. It can easily integrate with CI/CD pipelines, making it suitable for organizations adopting DevOps practices.

  2. Perform thorough testing to identify all vulnerabilities. While IBM AppScan is considered a great product, it may not identify all vulnerabilities. To ensure maximum effectiveness, users recommend conducting proper tests and utilizing specific use cases before moving into production.

  3. Benefit from IBM's expertise in software solutions. IBM is a leader in providing software solutions, and users believe that IBM AppScan is a prime example of their pioneering work. They recommend using IBM AppScan to identify security issues and vulnerabilities within applications. The comprehensive report generated by IBM AppScan helps in understanding and addressing these issues effectively.

In summary, users recommend using IBM AppScan for its wide range of security testing capabilities, suggest thorough testing to identify vulnerabilities, and highlight the benefits of IBM's expertise in software solutions.

Reviews

(1-6 of 6)
Companies can't remove reviews or game the system. Here's why

HCL AppScan: Things you wished you know before.

Rating: 7 out of 10
January 10, 2023
Verified User
Vetted Review
Verified User
HCL AppScan
1 year of experience
This application helps to perform Dynamic Application Scan, in which the HCL AppScan dynamically navigates through the site and finds any vulnerabilities or fixes that can be done to prevent any future attack. The best thing about this application is the variety of configurations we can do depending on the scenario and the ping capacity.
  • Test the application
  • Explore the application for vulnerabilities
  • Runs automatic scans
I would say that HCL AppScan is very simple to understand and use since it uses a user-friendly interface and the terminologies that are used in the interface of the application is very clear. We can automate a scan with any third party like Jenkins. The fact, I don't like is the time takes to execute the application, it should be better.

An Automated and Integrated Platform that provides a Holistic Visibility into the Security

Rating: 10 out of 10
December 23, 2022
SG
Vetted Review
Verified User
HCL AppScan
2 years of experience
HCL AppScan is an automated and integrated platform that provides a holistic visibility into the security posture of an application. It enables protection of business-critical applications from security threats, vulnerabilities, and compliance violations. It offers best protection in the market right now. HCL AppScan enables our organizations to secure our mobile and web apps by identifying vulnerabilities and flaws before they are deployed into production environment.
  • Easy to manage
  • Easy to use
  • Easy to connect to our CI/CD pipeline
  • Good documentation
  • Trustful assessment
In HCL AppScan automation maintain a reasonable pace of review and remediation of flaws for our apps. HCL AppScan is a cloud-based enterprise mobile application security testing solution for Android and iOS applications developed using Java, .Net or Objective-C. So it covers all our area and It consists of three components: AppScan Source Edition for developing and testing apps internally, AppScan Standard Edition for testing internally or externally, and AppScan Enterprise Edition for large enterprises who need to secure their entire mobile application portfolio across the organization with multiple device types.

A tool that can perform diagnostics according to the application specifications.

Rating: 8 out of 10
June 07, 2022
BR
Vetted Review
Verified User
HCL AppScan
3 years of experience
For years I have compared it with products from other companies and free products, but to be honest, the test patterns have become commoditized and I don't think there is a big difference in any product. In addition, the report can be shared with development members, leading to problem-solving.
  • Programming function.
  • Vulnerability diagnostic report.
  • I think it is convenient to be able to diagnose vulnerabilities regularly with the scheduling function.
Web applications these days have evolved too much and have become extremely complex. With AppScan, the configuration can be done through the GUI by using functions such as "login management" and "multi-step operation". To be honest, there are some parts of these functions that are difficult to understand, but I think we have to wait for more for the arrival of AI.

HCL AppScan insights

Rating: 7 out of 10
November 07, 2021
FG
Vetted Review
Verified User
HCL AppScan
1 year of experience
HCL AppScan provides mobile application scan with predefined templates integration with common code repositories supported Supports 13+ languages including C/C++, COBOL, ColdFusion, Java™ , Android, JSP, JavaScript, Perl, PHP, PL/SQL/T-SQL, C#, ASP.NET, and VB.NET on the other hand, it requires upfront planning for setup and configuration the recording of the application is crucial to have valuable test completion There is quite a complex list of supported browsers May be resource intensive which can cause long run-times for dynamic scans the application crashes sometimes
  • learns behavior of each application to test application-specific vulnerabilities
  • Provides mobile application scan with predefined templates
strengths : identifies Static and Dynamic Security vulnerabilities, has IDE plugins for ease of use like VS Plugin, Eclipse Plugin, IntelliJ, etc
Challenges : support build of code files prior to scan, offers limited static analysis features for data identification and runtime data tracking

HCL AppScan a reliable solution for all your application security needs

Rating: 8 out of 10
July 30, 2021
Verified User
Vetted Review
Verified User
HCL AppScan
3 years of experience
HCL AppScan (formerly from IBM) is an application security solution that helps my team to review security flaws and bugs in developing applications. HCL AppScan is a source code analysis tool usually known as Static Application Security Testing (SAST) Tool. The solution is well-engineered and is rated among the leaders in the market. It helped my team reduce errors and ensure we followed security best practices in our software development cycle.
  • Vulnerability reporting
  • Static code analysis
  • Remediation
  • DevSecOps
HCL AppScan (formerly from IBM) is well suited for reducing security flaws in my team's secure code development. The software identifies a lot of issues automatically which helps us reduce delivery time and prevent security breaches. HCL AppScan (formerly from IBM) lacks innovation and automation functionalities, while other tools offer artificial intelligence-driven analysis that helps the team reduce time and money. Also, there is a need to reduce false-positives generated by the solution

AppScan helps up keep Web Apps in Compliance

Rating: 8 out of 10
September 12, 2018
SS
Vetted Review
Verified User
HCL AppScan
14 years of experience
We use IBM AppScan as part of our overall vulnerability management program. These assessments are in depth and use several tools, AppScan being the tool we use to look for application vulnerabilities in our Web applications.
We do a pre-production security assessment on all applications before they go live in our environment. In addition we do regularly repeated scans which primarily look for patching compliance and new vulnerabilities that may affect these applications.
  • AppScan works well in finding application vulnerabilities such as SQL injection, cross-site scripting and all of the OWASP top 10.
  • Flexible reporting allows us to generate executive reports for application owners as well as separate technical reports for developers and system engineers.
  • Technical reports include remediation information and cross reference CVSS scores
  • Because it maintains data on all repeated assessments it helps us to do trending and metrics on compliance
This application is well suited for all web applications with the primary difficulty being that is does not handle federated logins.
However since we have validated our federation and vetted it well it is not a critical issue to bypass federation for scanning a site, only an inconvenience as we have to setup bypass authentication and then remove so that is cannot be used by an attacker.
Return to navigation