FortiWeb Cloud Virtual Patching
FortiWeb Cloud Virtual Patching simplifies the process of addressing vulnerabilities detected during DAST scans. It combines FortiDAST's detection capabilities with FortiWeb Cloud's custom rule creation, allowing you to address security issues. The following fuzzers are supported for virtual patching.
-
Server-Side Template Injection (SSTI)
-
Expressive Language Injection (ELI)
-
LDAP Injection (LDAPI)
-
ASP PHP Code Injection
-
Local File Inclusion (LFI)
Perform the following steps to integrate FortiWeb Cloud with FortiDAST.
-
Navigate to DAST Settings > FortiWebCloud Virtual Patching section.
-
Add API Key Secret generated from FortiWeb Cloud. See FortiWeb Cloud User Guide > Settings.
-
Click Validate.
Virtual patching is supported for FortiWeb Cloud only. |