Virtual Patching
This tab displays a list of supported vulnerabilities available for virtual patching discovered during the last scan. For each vulnerability, URL, Vulnerability Name, Severity, Details, Type (Parameter or URL), and Signature is displayed.
Click Details icon to view detailed information.
A label next to the URL indicates the patch status.
-
New: Newly identified vulnerability after a scan.
-
Patched: Patch has been applied in FortiAppSec Cloud WAF.
-
Not Patched: Patch was deleted in FortiAppSec Cloud WAF but is still present in FortiDAST.
Applying Virtual Patch
|
|
The target application must be added in FortiAppSec Cloud WAF before applying virtual patches. See FortiAppSec Cloud User Guide > WAF setup. |
Perform the following steps to apply a virtual patch.
-
Ensure the FortiAppSec Cloud WAF is integrated with FortiDAST. See FortiAppSec Cloud WAF Virtual Patching.
-
Go to Scans Overview.
-
Select a asset and click Virtual Patching tab.
-
Select a vulnerability and click Apply.
-
You can review the applied patch by navigating to FortiAppSec Cloud > WAF > Application > Advanced Applications > Custom Rule. See FortiAppSec Cloud User Guide > Custom Rule.
Deleting Virtual Patch
Perform the following steps to delete a virtual patch.
-
Go to Scans Overview.
-
Select a asset and click Virtual Patching tab.
-
Select a vulnerability and click Delete.
Deleting a patch in FortiDAST will only delete the filter in FortiAppSec Cloud WAF custom rule.
Synchronization
Click Sync to update the latest patch status from FortiAppSec Cloud WAF. Patch that was deleted in FortiAppSec Cloud WAF but present in FortiDAST are marked Not Patched.