WebInspect's REST API can be accessed without authentication.
Description
HP WebInspect, a web application security testing tool, is installed on the remote Windows host and running the REST API used for integration and access. By default the REST API is not configured to use authentication to control access. A remote attacker could access the API to gain information about the system and potentially modify WebInspect's settings and configuration.
Solution
Either limit incoming traffic to this port or enable authentication.