Skip to content

Qualys Enhances REST API Security with Swagger and OpenAPI Support

Automatically test REST APIs with Swagger or OpenAPI. Find and fix common security flaws early in the development cycle.

In this picture I can see the buildings. On the right I can see some people were standing near to...
In this picture I can see the buildings. On the right I can see some people were standing near to the fencing. In front of them I can see many peoples were walking on the road. On the road I can see the traffic signal, traffic cones and street lights. In the top left corner there is a sun. In the top right corner I can see the sky and clouds.

Qualys Enhances REST API Security with Swagger and OpenAPI Support

Qualys Web Application Scanning (WAS) has enhanced its REST API testing capabilities, now supporting Swagger and OpenAPI specifications. This update, released in April 2020, enables automatic security testing of API endpoints using Swagger or OpenAPI files.

The new feature allows for the detection of common application security flaws in REST APIs, such as SQL injection, command injection, and remote code execution. This is made possible by the addition of new informational QIDs: QID 150195 and QID 150197.

Qualys WAS also supports Postman Collections for functional testing of REST APIs. Additionally, it offers plugins for CI/CD tools like Jenkins, Bamboo, and TeamCity, enabling automated security testing in continuous integration and deployment environments for both web applications and REST APIs.

By supporting Swagger and OpenAPI, Qualys WAS aligns with OWASP's Proactive Controls v2, recommending early and frequent security verification in the software development life cycle. This update underscores the importance of REST API security, given the shared application-layer vulnerabilities with web applications.

Read also:

Latest