Try our new research platform with insights from 80,000+ expert users
reviewer1495479 - PeerSpot reviewer
Senior Manager, IT Test Automation Engineering at a outsourcing company with 10,001+ employees
Real User
Offers a few specific development languages but needs more languages and lacks good technical support services
Pros and Cons
  • "The solution offers services in a few specific development languages."
  • "They have to improve support."

What is most valuable?

The solution offers services in a few specific development languages.

What needs improvement?

They have to improve support. Their support before, when it was IBM, was very good technical support. However, now, it's very bad.

They could add more language coverage. They don't cover so many development languages. They really should be covering more. If they did, it would be a huge improvement.

How are customer service and support?

The technical support is no longer any good. It's gone downhill since they were under IBM. Now, we are no longer satisfied with their level of service and we hope they will improve their services in the future.

Which other solutions did I evaluate?

I'm currently looking into Checkmarx. I'm evaluating their offering to see how it compares. This product lacks in many areas, and so we are looking at other options.

Buyer's Guide
HCL AppScan
February 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What other advice do I have?

I don't have information on the relationship HCL has with my company. My understanding is they are just a vendor for us.

In general, I would rate them at a six out of ten. There are many areas in which they could improve, including by adding more languages and re-vamping their technical support. They are lacking in a lot of areas.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
VijayKumar16 - PeerSpot reviewer
Global Business Development Executive - Applications, Data & AI Practice at Kyndryl
Real User
Stable and scalable but not user-friendly
Pros and Cons
  • "AppScan is stable."
  • "AppScan is too complicated and should be made more user-friendly."

What is our primary use case?

I mainly use AppScan for vulnerability scanning and database bridging.

What needs improvement?

AppScan is too complicated and should be made more user-friendly.

For how long have I used the solution?

I've been using HCL AppScan for three to four years.

What do I think about the stability of the solution?

AppScan is stable.

What do I think about the scalability of the solution?

AppScan is scalable.

How are customer service and support?

HCL's technical support is ok, but it could be faster and more responsive.

How was the initial setup?

The initial setup was complex and took about a day and a half.

What other advice do I have?

I would rate AppScan four out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
HCL AppScan
February 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
PeerSpot user
Security Consultant at a tech vendor with 501-1,000 employees
Vendor
It detects cross-site scripting and SQL injection issues better than other tools.

What is most valuable?

The most valuable feature of this product is its capability to detect XSS and SQL injection.

How has it helped my organization?

Security issues reported by the tool help customers write secure code.

What needs improvement?

  • Better detection of DOM-based XSS
  • Better remediation guidance using code examples and contexts

For how long have I used the solution?

I have used it for four years.

What was my experience with deployment of the solution?

I did not encounter any deployment, stability or scalability issues.

Which solution did I use previously and why did I switch?

I previously used HP WebInspect and Qualys.

I prefer Appscan, as it much more user friendly, and it detects cross-site scripting and SQL injection issues much better than other tools in the market. Also, it has a lower false-positive count than others.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user844479 - PeerSpot reviewer
People Leader Of Cyber Strategy And Solutions at a insurance company with 10,001+ employees
Real User
We are now deploying less defects to production
Pros and Cons
  • "We leverage it as a quality check against code."
  • "We are now deploying less defects to production."

    What is our primary use case?

    It is used as a last check before moving code to production. Therefore, it is used as a developer tool.

    How has it helped my organization?

    With AppScan, we are now deploying less defects to production.

    What is most valuable?

    We leverage it as a quality check against code.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    No stability issues.

    How are customer service and technical support?

    We have a strong partnership with IBM. Their tech support is very knowledgeable.

    Which solution did I use previously and why did I switch?

    We were using something else (a competing product of IBM), but we switched to AppScan because it is reliable.

    What other advice do I have?

    Most important criteria when selecting a vendor: At the end of the day, it would have to be the support and relationship. There are a lot of smart people out there building products which do things. However, not everyone can use them, and without having someone to call, it is sort of its own disadvantage. 

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    PeerSpot user
    Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
    Consultant
    Top 20
    A low rate of false positives translates to a savings in time
    Pros and Cons
    • "This solution saves us time due to the low number of false positives detected."
    • "IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."

    What is our primary use case?

    The primary use case is to detect time-based Blind SQL Injection attacks, as well as Error-Based Injection attacks. The SQL injection attack is my favorite and I have more expertise in this vulnerability.

    How has it helped my organization?

    This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.

    What is most valuable?

    The most valuable feature is that it achieves a very low false-positive detection rate.

    What needs improvement?

    While I did not identify any specific bugs in this application. I did find that sometimes a restart was needed to deal with unresponsiveness means when AppScan is in a hang situation, this happens usually when you select a large number of sources. 

    IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.

    For how long have I used the solution?

    One to three years.

    Which solution did I use previously and why did I switch?

    We previously used Burp Suite. This application is best for static scanning.

    How was the initial setup?

    Complex

    Which other solutions did I evaluate?

    We also evaluated Acunetix and Nexpose.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user634947 - PeerSpot reviewer
    Application Security Consultant at a financial services firm with 10,001+ employees
    Real User
    We can find security vulnerabilities.
    Pros and Cons
    • "It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
    • "We would like to integrate with some of the other reporting tools that we're planning to use in the future."

    How has it helped my organization?

    The benefits are that we that we can find security vulnerabilities fast, get that back to development teams, and report on those. They can then act, fix the issues, and we'll have a secure code in place.

    What is most valuable?

    It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.

    What needs improvement?

    We would like to be able to integrate to some of the other tools that we are using. That would be great. We would like to integrate with some of the other reporting tools that we're planning to use in the future.

    What do I think about the stability of the solution?

    I think it's quite stable.

    What do I think about the scalability of the solution?

    So far scalability is pretty good.

    How is customer service and technical support?

    We're really happy with technical support. They are great and very responsive.

    How was the initial setup?

    I was not involved in the initial setup.

    What other advice do I have?

    What I look for most in a vendor is the product, the offer, the service, the vendor service, and after sale support.

    I would definitely recommend this product.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1415661 - PeerSpot reviewer
    General Manager at a consultancy with 51-200 employees
    Real User
    Allows for dynamic scanning but lacks easy CI/CD integration
    Pros and Cons
    • "It identifies all the URLs and domains on its own and then performs tests and provides the results."
    • "One thing which I think can be improved is the CI/CD Integration"

    What is our primary use case?

    We perform more dynamic scanning using AppScan. We set up a scan, perform it and get the results, and then give the results back to our customer.

    Within our organization, there are four members of the team who are using it.

    Currently, we are satisfied with AppScan but I am sure there are better alternatives available because this is a very old product. It's been on market for more than ten years now. I am sure there are a lot of new age products that are more scalable and cloud-based. Although we are using it and will probably continue to do so moving forward, I think there are better alternatives on the market now.

    How has it helped my organization?

    It takes care of our dynamic scanning needs. 

    What is most valuable?

    It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive. 

    What needs improvement?

    There are some false positives, which need to be removed, but this is common with all types of scanners.

    One thing which I think can be improved is the CI/CD Integration. There is a CI/CD Integration model, but I guess they are deliberately not using it currently. There are challenges when integrating AppScan with CI/CD because sometimes the activation plus the login mechanism provided doesn't work properly. Sometimes a login mechanism fails and then the whole scan fails. It's difficult to integrate with CI/CD.

    For how long have I used the solution?

    I have been using this solution for almost two years.

    What do I think about the scalability of the solution?

    Scalability-wise, I'm not sure because you can buy the licenses depending on how many scans you want to do, but yes, it's scalable. I can do multiple scans simultaneously, but we have not tried more than that. I cannot tell you whether it can scale up to more than maybe two, three, or four simultaneous scans. We have not tested that.

    How are customer service and technical support?

    The technical support is quite good. They always respond quickly.

    How was the initial setup?

    Installation is pretty straightforward. Deployment only took a day or two.

    What about the implementation team?

    We deployed it ourselves. Even one person can manage it so that's not an issue, but currently, we have four users who perform the activities and scans because of the volume of requests that we received from different businesses.

    What other advice do I have?

    I would recommend AppScan to other businesses. In a small-scale setup, it works perfectly fine, but if you are a larger organization with a lot of applications and you need to do CI/CD, then it's probably not the solution for you. Conversely, in a small organization with less than 20 applications, this will work pretty nicely.

    On a scale from one to ten, I would give this solution a rating of seven.

    If they can integrate with CI/CD and make the log-in mechanism a little smoother, they should be able to scale it up. If they could integrate with the CI/CD pipeline and make the scans a little faster, then I would give it a higher rating.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Chief researcher at INSEC Security
    Real User
    The depth was low, but the part that the user could miss was also diagnosed

    What is our primary use case?

    External and internal web application vulnerability scan.

    How has it helped my organization?

    • We were able to easily diagnose a large number of web applications automatically.
    • The depth was low, but the part that the user could miss was also diagnosed.

    What is most valuable?

    AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.

    What needs improvement?

    It would be nice to be able to specify the parameter values ​​used in the login sequence function.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
    Updated: February 2025
    Buyer's Guide
    Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.