Virtual Patching
This tab displays a list of supported vulnerabilities available for virtual patching discovered during the last scan. For each vulnerability, URL, Vulnerability Name, Severity, Details, Type (Parameter or URL), and Signature is displayed.
Click Details icon to view detailed information.
A label next to the URL indicates the patch status.
-
New: Newly identified vulnerability after a scan.
-
Patched: Patch has been applied in FortiWeb Cloud.
-
Not Patched: Patch was deleted in FortiWeb Cloud but is still present in FortiDAST.
Applying Virtual Patch
The target application must be added in FortiWeb Cloud before applying virtual patches. See FortiWeb Cloud User Guide > Onboarding applications. |
Perform the following steps to apply a virtual patch.
-
Ensure the FortiWeb Cloud is integrated with FortiDAST. See FortiWeb Cloud Virtual Patching.
-
Go to Scans Overview.
-
Select a asset and click Virtual Patching tab.
-
Select a vulnerability and click Apply.
-
You can review the applied patch by navigating to FortiWebCloud > Application > Advanced Rules > Custom Patch. See FortiWeb Cloud User Guide > Custom Rule.
Deleting Virtual Patch
Perform the following steps to delete a virtual patch.
-
Go to Scans Overview.
-
Select a asset and click Virtual Patching tab.
-
Select a vulnerability and click Delete.
Deleting a patch in FortiDAST will only delete the filter in FortiWeb Cloud custom rule.
Synchronization
Click Sync to update the latest patch status from FortiWeb Cloud. Patch that was deleted in FortiWeb Cloud but present in FortiDAST are marked Not Patched.