Try our new research platform with insights from 80,000+ expert users
it_user840909 - PeerSpot reviewer
Managing director at Accenture
Real User
It indicates several grades of code vulnerabilities, so we can focus on the most severe first
Pros and Cons
  • "It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code."

    What is our primary use case?

    It is used for a DevOps environment, to perform a security profile, a code profile assessment. When you are building your software code, before finishing the build process and deploying to production, we run AppScan to figure out any security vulnerabilities in the code. It's called static analysis of the code.

    How has it helped my organization?

    It decreases the operational risk, security risk, a lot. In fact, when we first used it, the number of vulnerability alerts generated by the tool was huge. As time goes on, we can decrease those vulnerabilities because we learn from it. So, in the next release of the software, or new software that we have to develop, we know upfront that we should take care of some of the characteristics of the software.

    What is most valuable?

    It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code.

    What needs improvement?

    One thing that we would like in this tool is that it keeps ahead of the security guys, because one big advantage of this tool is that it always offers updates. Security is a process, you mitigate a risk, but the malware guys, they're trying to find another security hole in your environment. And the technology is evolving. So new security vulnerabilities are in the software. The point is, I hope that IBM continue, in improving and launching new versions, new upgrades, that can mitigate those security risks. 

    That's the most important value. It's not the tool itself, but the continuous enhancement of the tool. That's why we recommended this tool.

    Buyer's Guide
    HCL AppScan
    May 2025
    Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
    851,823 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    It's pretty stable. No issues as far as I can remember. 

    What do I think about the scalability of the solution?

    It's scalable. In the beginning, we found some issues regarding installing the tool in an open-source Jenkins environment - Jenkins is a tool for open-source. Jenkins and other tools, they automate the process. Those tools call AppScan in a way to generate a proper time to do this. But after a couple of discussions, we solved the problem, so we don't have any issues anymore.

    How are customer service and support?

    I think it is pretty good. They answer in a very fast manner.

    How was the initial setup?

    It's pretty straightforward to install and use it.

    Which other solutions did I evaluate?

    One competitor that I remember, one of the last candidates in the evaluation process was Checkmarx. Those tools, especially from startups that come from Israel, they try to grab this market space that IBM dominates.

    That's why they have to take care in terms of the price; the price model. But other than that, it would be unbeatable.

    What other advice do I have?

    The most important criteria when selecting a vendor, first of all, is their capability to continuously invest in the development and enhancement of the software. We are in a very changing process, software is a very changing environment, in terms of the technology. If you develop a tool, launch this tool, but don't have enough commitment to upgrade, to continuously enhance, it's not worth it. That's why I think IBM has a good presence in this area.

    My advice would be, don't see only the cost. Try to see the capability of the tools and, besides that, as I have stressed in this review, the capability of the vendor to invest in enhancing and mitigating the risks that will come. New risks, new threats, security threats, will appear. If you don't have a company that is continuously enhancing its software, there will be a problem.

    I would rate this product a nine out of 10. The reason I don't give it a 10 is because AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost. But with the maintenance - and the maintenance is the most important, as I told you, because it has to continuously enhance the tool to mitigate the increasing malware in the future - IBM could recover the investment and meet their target margins in another way.

    Unfortunately, there is a big discussion if it is very expensive, to use it or not, and there are competitors. I see competitors trying to grab this market.

    But from the point of view of quality, very excellent quality, it's above all the tools that I have worked with.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    PeerSpot user
    PeerSpot user
    Security Consultant at a tech vendor with 501-1,000 employees
    Vendor
    It detects cross-site scripting and SQL injection issues better than other tools.

    What is most valuable?

    The most valuable feature of this product is its capability to detect XSS and SQL injection.

    How has it helped my organization?

    Security issues reported by the tool help customers write secure code.

    What needs improvement?

    • Better detection of DOM-based XSS
    • Better remediation guidance using code examples and contexts

    For how long have I used the solution?

    I have used it for four years.

    What was my experience with deployment of the solution?

    I did not encounter any deployment, stability or scalability issues.

    Which solution did I use previously and why did I switch?

    I previously used HP WebInspect and Qualys.

    I prefer Appscan, as it much more user friendly, and it detects cross-site scripting and SQL injection issues much better than other tools in the market. Also, it has a lower false-positive count than others.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    HCL AppScan
    May 2025
    Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
    851,823 professionals have used our research since 2012.
    it_user844479 - PeerSpot reviewer
    People Leader Of Cyber Strategy And Solutions at a insurance company with 10,001+ employees
    Real User
    We are now deploying less defects to production
    Pros and Cons
    • "We leverage it as a quality check against code."
    • "We are now deploying less defects to production."

      What is our primary use case?

      It is used as a last check before moving code to production. Therefore, it is used as a developer tool.

      How has it helped my organization?

      With AppScan, we are now deploying less defects to production.

      What is most valuable?

      We leverage it as a quality check against code.

      For how long have I used the solution?

      Less than one year.

      What do I think about the stability of the solution?

      No stability issues.

      How are customer service and technical support?

      We have a strong partnership with IBM. Their tech support is very knowledgeable.

      Which solution did I use previously and why did I switch?

      We were using something else (a competing product of IBM), but we switched to AppScan because it is reliable.

      What other advice do I have?

      Most important criteria when selecting a vendor: At the end of the day, it would have to be the support and relationship. There are a lot of smart people out there building products which do things. However, not everyone can use them, and without having someone to call, it is sort of its own disadvantage. 

      Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
      PeerSpot user
      it_user634947 - PeerSpot reviewer
      Application Security Consultant at a financial services firm with 10,001+ employees
      Real User
      We can find security vulnerabilities.
      Pros and Cons
      • "It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
      • "We would like to integrate with some of the other reporting tools that we're planning to use in the future."

      How has it helped my organization?

      The benefits are that we that we can find security vulnerabilities fast, get that back to development teams, and report on those. They can then act, fix the issues, and we'll have a secure code in place.

      What is most valuable?

      It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.

      What needs improvement?

      We would like to be able to integrate to some of the other tools that we are using. That would be great. We would like to integrate with some of the other reporting tools that we're planning to use in the future.

      What do I think about the stability of the solution?

      I think it's quite stable.

      What do I think about the scalability of the solution?

      So far scalability is pretty good.

      How is customer service and technical support?

      We're really happy with technical support. They are great and very responsive.

      How was the initial setup?

      I was not involved in the initial setup.

      What other advice do I have?

      What I look for most in a vendor is the product, the offer, the service, the vendor service, and after sale support.

      I would definitely recommend this product.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer1415661 - PeerSpot reviewer
      General Manager at a consultancy with 51-200 employees
      Real User
      Allows for dynamic scanning but lacks easy CI/CD integration
      Pros and Cons
      • "It identifies all the URLs and domains on its own and then performs tests and provides the results."
      • "One thing which I think can be improved is the CI/CD Integration"

      What is our primary use case?

      We perform more dynamic scanning using AppScan. We set up a scan, perform it and get the results, and then give the results back to our customer.

      Within our organization, there are four members of the team who are using it.

      Currently, we are satisfied with AppScan but I am sure there are better alternatives available because this is a very old product. It's been on market for more than ten years now. I am sure there are a lot of new age products that are more scalable and cloud-based. Although we are using it and will probably continue to do so moving forward, I think there are better alternatives on the market now.

      How has it helped my organization?

      It takes care of our dynamic scanning needs. 

      What is most valuable?

      It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive. 

      What needs improvement?

      There are some false positives, which need to be removed, but this is common with all types of scanners.

      One thing which I think can be improved is the CI/CD Integration. There is a CI/CD Integration model, but I guess they are deliberately not using it currently. There are challenges when integrating AppScan with CI/CD because sometimes the activation plus the login mechanism provided doesn't work properly. Sometimes a login mechanism fails and then the whole scan fails. It's difficult to integrate with CI/CD.

      For how long have I used the solution?

      I have been using this solution for almost two years.

      What do I think about the scalability of the solution?

      Scalability-wise, I'm not sure because you can buy the licenses depending on how many scans you want to do, but yes, it's scalable. I can do multiple scans simultaneously, but we have not tried more than that. I cannot tell you whether it can scale up to more than maybe two, three, or four simultaneous scans. We have not tested that.

      How are customer service and technical support?

      The technical support is quite good. They always respond quickly.

      How was the initial setup?

      Installation is pretty straightforward. Deployment only took a day or two.

      What about the implementation team?

      We deployed it ourselves. Even one person can manage it so that's not an issue, but currently, we have four users who perform the activities and scans because of the volume of requests that we received from different businesses.

      What other advice do I have?

      I would recommend AppScan to other businesses. In a small-scale setup, it works perfectly fine, but if you are a larger organization with a lot of applications and you need to do CI/CD, then it's probably not the solution for you. Conversely, in a small organization with less than 20 applications, this will work pretty nicely.

      On a scale from one to ten, I would give this solution a rating of seven.

      If they can integrate with CI/CD and make the log-in mechanism a little smoother, they should be able to scale it up. If they could integrate with the CI/CD pipeline and make the scans a little faster, then I would give it a higher rating.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      Chief researcher at INSEC Security
      Real User
      The depth was low, but the part that the user could miss was also diagnosed

      What is our primary use case?

      External and internal web application vulnerability scan.

      How has it helped my organization?

      • We were able to easily diagnose a large number of web applications automatically.
      • The depth was low, but the part that the user could miss was also diagnosed.

      What is most valuable?

      AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.

      What needs improvement?

      It would be nice to be able to specify the parameter values ​​used in the login sequence function.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      PeerSpot user
      Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
      Consultant
      Top 20
      A low rate of false positives translates to a savings in time
      Pros and Cons
      • "This solution saves us time due to the low number of false positives detected."
      • "IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."

      What is our primary use case?

      The primary use case is to detect time-based Blind SQL Injection attacks, as well as Error-Based Injection attacks. The SQL injection attack is my favorite and I have more expertise in this vulnerability.

      How has it helped my organization?

      This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.

      What is most valuable?

      The most valuable feature is that it achieves a very low false-positive detection rate.

      What needs improvement?

      While I did not identify any specific bugs in this application. I did find that sometimes a restart was needed to deal with unresponsiveness means when AppScan is in a hang situation, this happens usually when you select a large number of sources. 

      IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.

      For how long have I used the solution?

      One to three years.

      Which solution did I use previously and why did I switch?

      We previously used Burp Suite. This application is best for static scanning.

      How was the initial setup?

      Complex

      Which other solutions did I evaluate?

      We also evaluated Acunetix and Nexpose.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      PeerSpot user
      Security Consultant at a consultancy with 10,001+ employees
      Real User
      Simplifies our work by allowing us to do multiple website scans together
      Pros and Cons
      • "IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability."
      • "It has crashed at times."
      • "Scans become slow on large websites."
      • "Many silly false positives are produced."

      How has it helped my organization?

      IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability.

      What is most valuable?

      Many features are valuable but some features stand out, like using our own scripts, and capturing the authentication.

      What needs improvement?

      • It has crashed at times
      • Scans become slow on large websites
      • Many silly false positives are produced

      For how long have I used the solution?

      One to three years.

      What do I think about the stability of the solution?

      Yes, sometimes we encounter stability issues.

      What do I think about the scalability of the solution?

      Yes, sometimes we encounter scalability issues.

      How are customer service and technical support?

      I would rate tech support a seven out of 10.

      Which solution did I use previously and why did I switch?

      Yes. We switched because they made our work easier, with fewer false positives.

      How was the initial setup?

      It was simple, once we watched many video tutorials and read PDFs to learn about it.

      Which other solutions did I evaluate?

      Yes, I used with Acunetix and open source tools.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      Buyer's Guide
      Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
      Updated: May 2025
      Buyer's Guide
      Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.