PeerSpot user
Security Consultant at a consultancy with 10,001+ employees
Real User
Simplifies our work by allowing us to do multiple website scans together
Pros and Cons
  • "IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability."
  • "It has crashed at times."
  • "Scans become slow on large websites."
  • "Many silly false positives are produced."

How has it helped my organization?

IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability.

What is most valuable?

Many features are valuable but some features stand out, like using our own scripts, and capturing the authentication.

What needs improvement?

  • It has crashed at times
  • Scans become slow on large websites
  • Many silly false positives are produced

For how long have I used the solution?

One to three years.
Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,479 professionals have used our research since 2012.

What do I think about the stability of the solution?

Yes, sometimes we encounter stability issues.

What do I think about the scalability of the solution?

Yes, sometimes we encounter scalability issues.

How are customer service and support?

I would rate tech support a seven out of 10.

Which solution did I use previously and why did I switch?

Yes. We switched because they made our work easier, with fewer false positives.

How was the initial setup?

It was simple, once we watched many video tutorials and read PDFs to learn about it.

Which other solutions did I evaluate?

Yes, I used with Acunetix and open source tools.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Cloud Architect at a tech company with 1,001-5,000 employees
Real User
Provides a better integration for our ecosystem, but we are still waiting to see the roadmap
Pros and Cons
  • "It provides a better integration for our ecosystem."
  • "You can easily find particular features and functions through the UI."
  • "Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
  • "I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources."

What is our primary use case?

We integrate AppSense with Fortinet FortiGate Next-Generation Firewall products. This integration is new for us, but so far, we have had good results. However, it is a new integration. 

Fortinet has a lot of potential and integrations going on with IBM: QRadar, AppSense, and IBM Cloud.

How has it helped my organization?

It provides a better integration for our ecosystem. From a Fortinet perspective, this can lead to integration of selling our own products.

What is most valuable?

Its integration from a UI perspective. You can easily find particular features and functions through the UI. 

For its first initial release, the integration was pretty good.

What needs improvement?

More seamless integration with Fortinet's technologies as this would make our customers happy. At the moment, it is a good integration, but it is the first time that we have done it. Therefore, there needs to be more integration within our fabric, so it is less obvious.

Visibility is an issue for us. Our partners were not even aware that we had an integration with AppSense. They do not know we have integrations with some of IBM products. Part of this is our marketing budget is small compared to IBM's.

I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources. We are not like IBM, which is huge. We need to prioritize which engineer will work on which technology. 

With QRadar, it has better integration because we have been working with it for awhile and there is a roadmap. There are always new things coming out.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Unknown. We are too new to the product.

What do I think about the scalability of the solution?

Unknown. We are too new to the product.

How is customer service and technical support?

The IBM technical support staff are good.

What other advice do I have?

Have a look at the competitors as well. There is more than one vendor in the market. I would definitely do your due diligence.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Buyer's Guide
HCL AppScan
March 2024
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,479 professionals have used our research since 2012.
it_user844479 - PeerSpot reviewer
People Leader Of Cyber Strategy And Solutions at a insurance company with 10,001+ employees
Real User
We are now deploying less defects to production
Pros and Cons
  • "We leverage it as a quality check against code."
  • "We are now deploying less defects to production."

    What is our primary use case?

    It is used as a last check before moving code to production. Therefore, it is used as a developer tool.

    How has it helped my organization?

    With AppScan, we are now deploying less defects to production.

    What is most valuable?

    We leverage it as a quality check against code.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No stability issues.

    How are customer service and technical support?

    We have a strong partnership with IBM. Their tech support is very knowledgeable.

    Which solution did I use previously and why did I switch?

    We were using something else (a competing product of IBM), but we switched to AppScan because it is reliable.

    What other advice do I have?

    Most important criteria when selecting a vendor: At the end of the day, it would have to be the support and relationship. There are a lot of smart people out there building products which do things. However, not everyone can use them, and without having someone to call, it is sort of its own disadvantage. 

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Chief researcher at INSEC Security
    Real User
    The depth was low, but the part that the user could miss was also diagnosed

    What is our primary use case?

    External and internal web application vulnerability scan.

    How has it helped my organization?

    • We were able to easily diagnose a large number of web applications automatically.
    • The depth was low, but the part that the user could miss was also diagnosed.

    What is most valuable?

    AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.

    What needs improvement?

    It would be nice to be able to specify the parameter values ​​used in the login sequence function.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Cybersecurity Architecture and Technology Lead at Appxone
    Consultant
    A low rate of false positives translates to a savings in time
    Pros and Cons
    • "This solution saves us time due to the low number of false positives detected."
    • "IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."

    What is our primary use case?

    The primary use case is to detect time-based Blind SQL Injection attacks, as well as Error-Based Injection attacks. The SQL injection attack is my favorite and I have more expertise in this vulnerability.

    How has it helped my organization?

    This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.

    What is most valuable?

    The most valuable feature is that it achieves a very low false-positive detection rate.

    What needs improvement?

    While I did not identify any specific bugs in this application. I did find that sometimes a restart was needed to deal with unresponsiveness means when AppScan is in a hang situation, this happens usually when you select a large number of sources. 

    IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.

    For how long have I used the solution?

    One to three years.

    Which solution did I use previously and why did I switch?

    We previously used Burp Suite. This application is best for static scanning.

    How was the initial setup?

    Complex

    Which other solutions did I evaluate?

    We also evaluated Acunetix and Nexpose.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user634947 - PeerSpot reviewer
    Application Security Consultant at a financial services firm with 10,001+ employees
    Real User
    We can find security vulnerabilities.
    Pros and Cons
    • "It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
    • "We would like to integrate with some of the other reporting tools that we're planning to use in the future."

    How has it helped my organization?

    The benefits are that we that we can find security vulnerabilities fast, get that back to development teams, and report on those. They can then act, fix the issues, and we'll have a secure code in place.

    What is most valuable?

    It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.

    What needs improvement?

    We would like to be able to integrate to some of the other tools that we are using. That would be great. We would like to integrate with some of the other reporting tools that we're planning to use in the future.

    What do I think about the stability of the solution?

    I think it's quite stable.

    What do I think about the scalability of the solution?

    So far scalability is pretty good.

    How is customer service and technical support?

    We're really happy with technical support. They are great and very responsive.

    How was the initial setup?

    I was not involved in the initial setup.

    What other advice do I have?

    What I look for most in a vendor is the product, the offer, the service, the vendor service, and after sale support.

    I would definitely recommend this product.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user841920 - PeerSpot reviewer
    Business Development Manager at a tech services company with 10,001+ employees
    Reseller
    The static scans are good, though there is no central management
    Pros and Cons
    • "The static scans are good, and the SaaS as well."
    • "There is not a central management for static and dynamic."

    What is our primary use case?

    It is an application for security assessment or scanning for static environments.

    With all customers, it is performing well.

    What is most valuable?

    The static scans are good, and the SaaS as well. 

    What needs improvement?

    There is not a central management for static and dynamic. This would be great, at least with competition such as Micro Focus.

    For how long have I used the solution?

    Less than one year.

    How is customer service and technical support?

    The technical support is knowledgeable. However, our issue is not enough resources supporting our region. For Dubai, which is in the Gulf region, we need more technical support resources.

    How was the initial setup?

    The initial setup is not that complex.

    What other advice do I have?

    Most important criteria when choosing to partner with a company: I started working with IBM only one year back. When I started a partnership with them, IBM had the security portfolio which covered most of the region where my customers were. IBM has a name with the support along the quality of its products.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
    PeerSpot user
    it_user279198 - PeerSpot reviewer
    CEO at a government
    Vendor
    Easy to use and gives good insights into vulnerabilities

    What is our primary use case?

    We use it for all website development and web-based applications, as part of our development test cycle and QA.

    We also routinely use it on existing applications in production because, in terms of security and vulnerabilities, some of the latter exist on some of the platforms that we run. So we run it from time to time, to do some security checks, etc.

    How has it helped my organization?

    It has certainly improved our organization In terms of quality of solutions that are developed. 

    What is most valuable?

    I think it's easy to use and gives back some pretty good results, certainly for vulnerabilities.

    What needs improvement?

    I haven't actually used it personally, so I'm not sure that I would be able to answer this.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    It's pretty stable.

    What do I think about the scalability of the solution?

    It's scalable. We just did a review of the product itself, and it's something that we've decided to keep and continue using.

    How is customer service and technical support?

    Support: I'll just leave it at "good."

    How was the initial setup?

    This particular product is one of the easier products to set up.

    What other advice do I have?

    We've had a relationship for some time, over 20 years now, with IBM. It's really about the products, in terms of what we are looking for. That's really the deciding factor in deciding whether we'd use them for a particular solution.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2024
    Buyer's Guide
    Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.