HCL app scanner tool unable to access our web application

chitra manju 60 Reputation points
2025-02-05T07:44:59.6633333+00:00

We are hosting two web applications on Azure Cloud and utilizing Kubernetes for orchestration. Both applications are deployed using Docker containers and are performing security scans with HCL AppScan. However, we’ve encountered an issue where Application 2 seems to be penetrable during the scan, whereas Application 1 does not

Here are the details for both applications:

  • Application 1:
    • Frontend: React (with NPM)
      • Backend: Python (Flask)
        • Database: MySQL
          • Deployment: Docker container orchestrated with Kubernetes
          • Application 2:
            • Frontend: Angular (with NPM)
              • Backend: Java (possibly Spring Boot)
                • Database: PostgreSQL
                  • Deployment: Docker container orchestrated with Kubernetes

AS of now , we do not have firewall enabled , we use NSGs and have whitelisted the port numbers of the VAPT vendor .

The HCL app scanner can scrawl thru the application 2 but not applicaiton 1. We are doing VAPT tests for our application ,hence would need help on this .

Please guide.

 

Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
2,254 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.