Editing Vulnerabilities

After Fortify WebInspect assesses your application’s vulnerabilities, you may want to edit and save the results for a variety of reasons, including:

Editing a Vulnerable Session

To edit a vulnerable session:

  1. Do one of the following to select a session:

    • On the Findings tab in the Summary pane, right-click a vulnerable URL , or

    • On the navigation pane, right-click a session or URL.

  2. Select Edit Vulnerability from the shortcut menu.

    The Edit Vulnerabilities window opens.

  3. If the session includes multiple vulnerabilities, then select a vulnerability.

  4. To add an existing vulnerability to the session (that is, one that exists in the database), click Add Existing.

    1. On the Add Existing Vulnerability window, enter part of a vulnerability name, or a complete vulnerability ID number or type.

      Note: The * and % characters can be used interchangeably as wildcards. However, a wildcard is allowed only at the beginning, at the end, or at the beginning and end of a string. If placed within a string (such as "mic*soft,"), these characters will not function as wildcards.

    2. Click Search.

    3. Select one or more of the vulnerabilities returned by the search.

    4. Click OK.

  5. To add a custom vulnerability, click Add Custom.

    You can then edit the vulnerability as described in Step 7.

  6. To delete the vulnerability from the selected session, click Delete.

  7. To modify the vulnerability, select different options from the Vulnerability Detail section. You can also change the descriptions that appear on the Summary, Implication, Execution, Fix, and Reference Info tabs.

  8. Click OK to save the changes.