Technical Tip: How FortiDAST checks Vulnerabilities if WAF affects the scan
| Description | This article describes Vulnerability calculation check on FortiDAST, if WAF is inline, and the result is a false positive due to the block done by WAF. |
| Scope | FortiDAST. |
| Solution | Considering a situation where the FortiDAST scans an application hosted behind a cloud/on-prem WAF.
Screenshot refers to the access denied response by the WAF, and FortiDAST sees that as a Vulnerability.
Here is the corrected step-by-step breakdown of this flow:
Note: This is a case study, where the scan is done by FortiDAST and sees a Vulnerability which is the result of a blocked request by WAF inline. |

