Whitelist Vulnerabilities on the AppTrana WAAP

vinugayathri.chinnasamy@indusface.com Updated by vinugayathri.chinnasamy@indusface.com

AppTrana WAAP offers a Vulnerability Whitelisting feature that allows you to exclude non-critical or medium-level vulnerabilities from scan results.  

This functionality assists in managing your security assessments effectively by focusing on resolving critical issues while acknowledging and tracking less severe vulnerabilities. 

Accessing Vulnerability Whitelisting: 

To whitelist vulnerabilities in AppTrana WAAP, follow these steps: 

  1. Navigate to the "Detect" section within the AppTrana WAAP dashboard. Move to the list of Scan Summary section. 

  1. Select the URL and click the "Whitelist" button. 
  1. Upon clicking the "Whitelist" button, a popup screen will appear, allowing users to specify the following details: 
  • Time Period- Choose the duration for which the vulnerability will be whitelisted (e.g., specific timeframe or indefinitely). 
  • Reason- Enter the rationale for whitelisting the vulnerability. 

  1.  Click "Confirm Whitelist" to proceed. 

  1. A confirmation screen will appear to validate the whitelist request. Click Confirm

The changes will be reflected only from the next scan onwards.  

Upon successful whitelisting, the whitelist button for the particular URL will be disabled until the next scan. 

Category-Level Whitelisting: 

Users have the option to whitelist entire Vulnerability Categories instead of individual URLs. 

Unwhitelisting: 

  1. To remove a whitelisted vulnerability, users can click the "Unwhitelist" button in the Scan Summary section.  

  1. Enter a reason for unwhitelisting. 

  1. Confirm the action in the popup screen

If a vulnerability is whitelisted at the category level, it must be unwhitelisted at the category level only. 

Logging and Monitoring: 

Users can monitor whitelisting activities by accessing the Monitor -> Scan Summary section.

The section provides logs detailing whitelisted and unwhitelisted vulnerabilities, including the user responsible, timestamp, and additional details. 

Whitelisted Vulnerabilities Status 

Whitelisted vulnerabilities' details are displayed in the Dashboard under the "Vulnerability Status" section 

Also, in the "Detect" section under "Vulnerabilities Detected”. 

The list of whitelisted vulnerabilities is also accessible under the "Whitelist Vulnerabilities" tab within the Scan Summary section. 

How did we do?

API Scan Coverage for OWASP Top 10

API Request to Purge CDN Data

Contact

This site is protected by hCaptcha and its Privacy Policy and Terms of Service apply.