Try our new research platform with insights from 80,000+ expert users
reviewer1495479 - PeerSpot reviewer
Senior Manager, IT Test Automation Engineering at a outsourcing company with 10,001+ employees
Real User
Offers a few specific development languages but needs more languages and lacks good technical support services
Pros and Cons
  • "The solution offers services in a few specific development languages."
  • "They have to improve support."

What is most valuable?

The solution offers services in a few specific development languages.

What needs improvement?

They have to improve support. Their support before, when it was IBM, was very good technical support. However, now, it's very bad.

They could add more language coverage. They don't cover so many development languages. They really should be covering more. If they did, it would be a huge improvement.

How are customer service and support?

The technical support is no longer any good. It's gone downhill since they were under IBM. Now, we are no longer satisfied with their level of service and we hope they will improve their services in the future.

Which other solutions did I evaluate?

I'm currently looking into Checkmarx. I'm evaluating their offering to see how it compares. This product lacks in many areas, and so we are looking at other options.

Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

What other advice do I have?

I don't have information on the relationship HCL has with my company. My understanding is they are just a vendor for us.

In general, I would rate them at a six out of ten. There are many areas in which they could improve, including by adding more languages and re-vamping their technical support. They are lacking in a lot of areas.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1415661 - PeerSpot reviewer
General Manager at a consultancy with 51-200 employees
Real User
Allows for dynamic scanning but lacks easy CI/CD integration
Pros and Cons
  • "It identifies all the URLs and domains on its own and then performs tests and provides the results."
  • "One thing which I think can be improved is the CI/CD Integration"

What is our primary use case?

We perform more dynamic scanning using AppScan. We set up a scan, perform it and get the results, and then give the results back to our customer.

Within our organization, there are four members of the team who are using it.

Currently, we are satisfied with AppScan but I am sure there are better alternatives available because this is a very old product. It's been on market for more than ten years now. I am sure there are a lot of new age products that are more scalable and cloud-based. Although we are using it and will probably continue to do so moving forward, I think there are better alternatives on the market now.

How has it helped my organization?

It takes care of our dynamic scanning needs. 

What is most valuable?

It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive. 

What needs improvement?

There are some false positives, which need to be removed, but this is common with all types of scanners.

One thing which I think can be improved is the CI/CD Integration. There is a CI/CD Integration model, but I guess they are deliberately not using it currently. There are challenges when integrating AppScan with CI/CD because sometimes the activation plus the login mechanism provided doesn't work properly. Sometimes a login mechanism fails and then the whole scan fails. It's difficult to integrate with CI/CD.

For how long have I used the solution?

I have been using this solution for almost two years.

What do I think about the scalability of the solution?

Scalability-wise, I'm not sure because you can buy the licenses depending on how many scans you want to do, but yes, it's scalable. I can do multiple scans simultaneously, but we have not tried more than that. I cannot tell you whether it can scale up to more than maybe two, three, or four simultaneous scans. We have not tested that.

How are customer service and technical support?

The technical support is quite good. They always respond quickly.

How was the initial setup?

Installation is pretty straightforward. Deployment only took a day or two.

What about the implementation team?

We deployed it ourselves. Even one person can manage it so that's not an issue, but currently, we have four users who perform the activities and scans because of the volume of requests that we received from different businesses.

What other advice do I have?

I would recommend AppScan to other businesses. In a small-scale setup, it works perfectly fine, but if you are a larger organization with a lot of applications and you need to do CI/CD, then it's probably not the solution for you. Conversely, in a small organization with less than 20 applications, this will work pretty nicely.

On a scale from one to ten, I would give this solution a rating of seven.

If they can integrate with CI/CD and make the log-in mechanism a little smoother, they should be able to scale it up. If they could integrate with the CI/CD pipeline and make the scans a little faster, then I would give it a higher rating.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
PeerSpot user
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
Consultant
Top 20
A low rate of false positives translates to a savings in time
Pros and Cons
  • "This solution saves us time due to the low number of false positives detected."
  • "IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."

What is our primary use case?

The primary use case is to detect time-based Blind SQL Injection attacks, as well as Error-Based Injection attacks. The SQL injection attack is my favorite and I have more expertise in this vulnerability.

How has it helped my organization?

This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.

What is most valuable?

The most valuable feature is that it achieves a very low false-positive detection rate.

What needs improvement?

While I did not identify any specific bugs in this application. I did find that sometimes a restart was needed to deal with unresponsiveness means when AppScan is in a hang situation, this happens usually when you select a large number of sources. 

IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.

For how long have I used the solution?

One to three years.

Which solution did I use previously and why did I switch?

We previously used Burp Suite. This application is best for static scanning.

How was the initial setup?

Complex

Which other solutions did I evaluate?

We also evaluated Acunetix and Nexpose.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chief researcher at INSEC Security
Real User
The depth was low, but the part that the user could miss was also diagnosed

What is our primary use case?

External and internal web application vulnerability scan.

How has it helped my organization?

  • We were able to easily diagnose a large number of web applications automatically.
  • The depth was low, but the part that the user could miss was also diagnosed.

What is most valuable?

AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.

What needs improvement?

It would be nice to be able to specify the parameter values ​​used in the login sequence function.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user840837 - PeerSpot reviewer
Manager at a tech vendor with 501-1,000 employees
Real User
Scalable and powerful, helps find errors in the code base

What is our primary use case?

Our clients use it to try to find errors in base code, and also to find how solutions work together.

I believe they have on-premise usage; they are local government, so they are not very used to using the cloud.

How has it helped my organization?

I'm mainly working on the licensing side and not the technical side, so I don't get this kind of feedback.

What is most valuable?

Scalability, and it's a very powerful tool.

What needs improvement?

I believe there are improvements that can be made, but I'm not aware of those kinds of things.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's stable.

What do I think about the scalability of the solution?

For the market in Finland, when we are talking about a mid-size company, it equals a small company here in the USA, but they are mainly from 1,000 users to 10,000 users.

How is customer service and technical support?

Tech support is responsive. With the local support I get all the help I need. I'm a former IBMer, so I know the right contacts, so it's quite simple to work.

How was the initial setup?

I think it's a little bit complex, and that's quite a common issue with most of the IBM products.

Which other solutions did I evaluate?

Some of the customers are using office open-source tools, but most are not using a tool at all. So, that's the competition. Of course, they are thinking about return on investment because it's quite an expensive tool and they won't take it back.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user841920 - PeerSpot reviewer
Business Development Manager at a tech services company with 10,001+ employees
Reseller
The static scans are good, though there is no central management
Pros and Cons
  • "The static scans are good, and the SaaS as well."
  • "There is not a central management for static and dynamic."

What is our primary use case?

It is an application for security assessment or scanning for static environments.

With all customers, it is performing well.

What is most valuable?

The static scans are good, and the SaaS as well. 

What needs improvement?

There is not a central management for static and dynamic. This would be great, at least with competition such as Micro Focus.

For how long have I used the solution?

Less than one year.

How is customer service and technical support?

The technical support is knowledgeable. However, our issue is not enough resources supporting our region. For Dubai, which is in the Gulf region, we need more technical support resources.

How was the initial setup?

The initial setup is not that complex.

What other advice do I have?

Most important criteria when choosing to partner with a company: I started working with IBM only one year back. When I started a partnership with them, IBM had the security portfolio which covered most of the region where my customers were. IBM has a name with the support along the quality of its products.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
SeniorCl3552 - PeerSpot reviewer
Senior Cloud Architect at a tech company with 1,001-5,000 employees
Real User
Provides a better integration for our ecosystem, but we are still waiting to see the roadmap
Pros and Cons
  • "It provides a better integration for our ecosystem."
  • "You can easily find particular features and functions through the UI."
  • "Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
  • "I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources."

What is our primary use case?

We integrate AppSense with Fortinet FortiGate Next-Generation Firewall products. This integration is new for us, but so far, we have had good results. However, it is a new integration. 

Fortinet has a lot of potential and integrations going on with IBM: QRadar, AppSense, and IBM Cloud.

How has it helped my organization?

It provides a better integration for our ecosystem. From a Fortinet perspective, this can lead to integration of selling our own products.

What is most valuable?

Its integration from a UI perspective. You can easily find particular features and functions through the UI. 

For its first initial release, the integration was pretty good.

What needs improvement?

More seamless integration with Fortinet's technologies as this would make our customers happy. At the moment, it is a good integration, but it is the first time that we have done it. Therefore, there needs to be more integration within our fabric, so it is less obvious.

Visibility is an issue for us. Our partners were not even aware that we had an integration with AppSense. They do not know we have integrations with some of IBM products. Part of this is our marketing budget is small compared to IBM's.

I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources. We are not like IBM, which is huge. We need to prioritize which engineer will work on which technology. 

With QRadar, it has better integration because we have been working with it for awhile and there is a roadmap. There are always new things coming out.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Unknown. We are too new to the product.

What do I think about the scalability of the solution?

Unknown. We are too new to the product.

How is customer service and technical support?

The IBM technical support staff are good.

What other advice do I have?

Have a look at the competitors as well. There is more than one vendor in the market. I would definitely do your due diligence.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user279198 - PeerSpot reviewer
CEO at a government
Vendor
Easy to use and gives good insights into vulnerabilities

What is our primary use case?

We use it for all website development and web-based applications, as part of our development test cycle and QA.

We also routinely use it on existing applications in production because, in terms of security and vulnerabilities, some of the latter exist on some of the platforms that we run. So we run it from time to time, to do some security checks, etc.

How has it helped my organization?

It has certainly improved our organization In terms of quality of solutions that are developed. 

What is most valuable?

I think it's easy to use and gives back some pretty good results, certainly for vulnerabilities.

What needs improvement?

I haven't actually used it personally, so I'm not sure that I would be able to answer this.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's pretty stable.

What do I think about the scalability of the solution?

It's scalable. We just did a review of the product itself, and it's something that we've decided to keep and continue using.

How is customer service and technical support?

Support: I'll just leave it at "good."

How was the initial setup?

This particular product is one of the easier products to set up.

What other advice do I have?

We've had a relationship for some time, over 20 years now, with IBM. It's really about the products, in terms of what we are looking for. That's really the deciding factor in deciding whether we'd use them for a particular solution.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.