IBM Rational Web application security software helps IT and security professionals protect against the threat of attacks and data breaches. If you use applications to collect or exchange sensitive or personal data, your job as a security professional is harder now than ever before. Involving quality assurance and development in the security testing process results in higher-quality, more secure applications at a reasonable cost.
Rational offers a combination of static and dynamic Web application security testing solutions designed to provide the most comprehensive approach for assessing vulnerabilities in networked applications and critical Web sites. IBM Rational AppScan® can be used for Web application vulnerability scanning in all stages of development and by testers with or without security expertise.
Rational AppScan products provide:
- Static analysis security testing to identify vulnerabilities at the source
- Automated Web application scanning and testing for all common Web application vulnerabilities, including WASC threat classification - such as SQL-Injection, Cross-Site Scripting, and Buffer Overflow - and intelligent fix recommendations to ease remediation
- Detection of Website embedded Malware
- Broad application coverage, including integrated Web services scanning, JavaScript execution (including Ajax), and parsing
- Advanced remediation capabilities, including a comprehensive task list necessary to fix issues uncovered during the scan
- Over 40 standard security compliance reports, including PCI Data Security Standard, ISO 17799 and ISO 27001, HIPAA, GLBA, and Basel II
Web application security products

Rational AppScan family overview
Learn more about the Rational AppScan family.

Rational AppScan Build Edition
Embeds web application security testing into the build management workflow.

Rational AppScan Developer Edition
Automates application security scanning for non-security professionals.

Rational AppScan Enterprise Edition
Web-based, multi-user Web application vulnerability testing and reporting solution used to scale security testing across the enterprise.

Rational AppScan Express Edition
Affordable Web application security for smaller organizations.

Rational AppScan OnDemand
Identifies and prioritizes Web application security vulnerabilities across the enterprise through an outsourced SaaS Model.

Rational AppScan OnDemand Production Site Monitoring
Monitors production Web content and sites for security vulnerabilities through an outsourced SaaS model.

Rational AppScan Reporting Console
Software that provides centralized reporting on Web application vulnerability data.

Rational AppScan Standard Edition
Automated Web application security testing for IT Security, auditors, and penetration testers.

Rational AppScan Source Edition
Helps prevent data breaches by locating security flaws in the source code of networked applications

Rational AppScan Tester Edition
An edition of Rational AppScan that seamlessly integrates Web application security testing into the current QA environment.

