IBM Security AppScan vs Qualys Web Application Scanning

IBM Security AppScan is ranked 5th in Application Security with 14 reviews vs Qualys Web Application Scanning which is ranked 10th in Application Security with 8 reviews. The top reviewer of IBM Security AppScan writes "The ease of use is key, the developers can actually use it and get results from dynamic testing". The top reviewer of Qualys Web Application Scanning writes "We’re a Linux shop and Qualys gave us good Linux vulnerability scanning; no experience with it on MSFT products". IBM Security AppScan is most compared with Fortify on Demand, Veracode and Checkmarx. Qualys Web Application Scanning is most compared with Acunetix Vulnerability Scanner, Veracode and IBM Security AppScan. See our IBM Security AppScan vs Qualys Web Application Scanning report.
Cancel
You must select at least 2 products to compare!
+Add products to compare
Most Helpful Review
Find out what your peers are saying about IBM Security AppScan vs Qualys Web Application Scanning and others in Application Security.
287,901 professionals have used our research since 2012.

Quotes From Members Comparing IBM Security AppScan vs Qualys Web Application Scanning

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
Pros
The static scans are good, and the SaaS as well.It provides a better integration for our ecosystem.You can easily find particular features and functions through the UI.We leverage it as a quality check against code.We are now deploying less defects to production.Usually when we deploy the application, there is a process for ethical hacking. The main benefit is that, the ethical hacking is almost clean, every time. So it's less cost, less effort, less time to production.It has certainly helped us find vulnerabilities in our software, so this is priceless in the end.I like the recording feature.

Read more »

It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools.We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not.Key features include: Cloud-based, so the installation is not so tedious. Easily deployed. Highly scalable. Comprehensive reporting.You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy.​QualysGuard web-based scanner is very useful for performing external penetration and PCI scans from remote locations.​By using QualysGuard, we are able to finish external scans with assured results in half the time.​​This product is designed for easy scalability and can easily scale up ​without major challenges.​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​

Read more »

Cons
There is not a central management for static and dynamic.Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products.I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources.I would love to see more containers. Many of the tools are great, they require an amount of configuration, setup and infrastructure. If most the applications were in a container, I think everything would be a little bit faster, because all our clients are now using containers.​IBM Security AppScan Source is rather hard to use​.There are so many lines of code with so many different categories that I am likely to get lost. ​It's a little bit basic when you talk about the Web Services. If AppScan improved its maturity on Web Services testing, that would be good.I think being able to search across more containers, especially some of the docker elements. We need a little tighter integration there. That's the only thing I can see at this point.

Read more »

The area of false positives could be improved. There are quite a number of false positives as compared to other solutions. They could probably fine tune the algorithm to be able to reduce the number of false positives being detected.In terms of the Policy Compliance model which they currently have, not all the platforms are being covered. If they could improve on the Policy Compliance model, since there are policies which are benchmarked against it, this will be helpful for us.The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes.They should try to include business logic vulnerabilities in the scanner testing.In certain cases, this product does have false positives, which the company should work on.

Read more »

Pricing and Cost Advice
AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost.

Read more »

Licensing was based on the number of assets that you want to scan on your network. You can also do licensing on subscription. On subscription, it is easier and more flexible. You tell Qualys that you want to move from the 1000 to 2000 band or the 3000 or 5000 band, then they will give you the quotation for it. Once you pay for it, applying the licensing is quite easy and effective.Pricing was reasonable and competitive. It was not too far above the other products.Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved.​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders​.Try the free trial of the product to understand the basic working mechanisms.​

Read more »

report
Use our free recommendation engine to learn which Application Security solutions are best for your needs.
287,901 professionals have used our research since 2012.
Ranking
RANKING
Views
12,929
Comparisons
8,638
Reviews
13
Followers
338
Avg. Rating
8.1
Views
7,501
Comparisons
4,178
Reviews
6
Followers
340
Avg. Rating
6.8
Top Comparisons
Top Comparisons
Compared 16% of the time.
Compared 11% of the time.
See more IBM Security AppScan competitors »
See more Qualys Web Application Scanning competitors »
Also Known As
Also Known AsRational AppScan, AppScanQualys WAS
Website/Video
Website/VideoIBM
Qualys
Overview
Overview

IBM Security AppScan enhances web application security and mobile application security, improves application security program management and strengthens regulatory compliance. By scanning your web and mobile applications prior to deployment, AppScan enables you to identify security vulnerabilities and generate reports and fix recommendations.

Qualys Web Application Scanning (WAS) is a cloud service that provides automated crawling and testing of custom web applications to identify vulnerabilities including cross-site scripting (XSS) and SQL injection. The automated service enables regular testing that produces consistent results, reduces false positives, and easily scales to secure a large number of websites. Proactively scans websites for malware infections, sending alerts to website owners to help prevent black listing and brand reputation damage.
OFFER
Learn more about IBM Security AppScan
Learn more about Qualys Web Application Scanning
Sample Customers
Sample CustomersEssex Technology Group Inc., Cisco, West Virginia University, APIS ITBskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Top Industries
Top Industries
VISITORS READING REVIEWS
Financial Services Firm
24%
Transportation Company
24%
Comms Service Provider
19%
Manufacturing Company
7%
VISITORS READING REVIEWS
Financial Services Firm
19%
Healthcare Company
12%
Comms Service Provider
11%
Media Company
8%
Company Size
Company Size
REVIEWERS
Midsize Enterprise
15%
Large Enterprise
85%
REVIEWERS
Small Business
8%
Midsize Enterprise
8%
Large Enterprise
85%
VISITORS READING REVIEWS
Small Business
14%
Midsize Enterprise
19%
Large Enterprise
67%
Find out what your peers are saying about IBM Security AppScan vs Qualys Web Application Scanning and others in Application Security.
Download now
287,901 professionals have used our research since 2012.
We monitor all Application Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.

Sign Up with Email