What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current integration list: confirm against vendor documentation
- API and specification import formats supported: verify
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Qualys Web Application Scanning is the application layer module of the Qualys platform. You register a web application as an asset, define its scope and authentication, and a scanner crawls it to build a map of pages, forms and parameters, then runs attack checks for injection, cross-site scripting, misconfiguration, information disclosure and transport weaknesses. The crawler executes JavaScript so script-generated navigation and single-page application views are reachable. API endpoints are covered by importing a specification such as Swagger or OpenAPI, or by supplying recorded traffic, which matters because APIs rarely expose links to crawl.
Scans run from the same sensor fleet as the rest of the platform: Qualys-hosted scanners for internet-facing applications, or virtual scanner appliances you deploy inside your own network for internal ones. The consequence is that web application findings land in the same asset inventory, tagging model and reporting engine as your host and cloud findings, which is the practical reason most organizations choose it. Findings can also be exported as rules to a web application firewall so an unpatched issue is mitigated at the edge while engineering works on a fix.
Where it fits
This sits with a central security or vulnerability management team, running on a schedule against production and staging applications across a large estate. It integrates into pipelines for release-time scanning, but full authenticated scans are too slow for per-commit use. It makes most sense where Qualys is already the system of record for vulnerabilities, so application risk does not need a separate console. You need an accurate application inventory, working authentication records and exclusion rules before results are trustworthy.
Strengths
- Web application findings share the asset model, tagging and dashboards used for infrastructure, which removes a whole reporting integration problem.
- Internal applications are covered by deploying scanner appliances.
- Specification-driven API scanning reaches endpoints a crawler would never discover.
- Compliance-oriented reporting is mature, including mappings that satisfy common audit requests.
Limitations
- Authorization flaws, business logic abuse and multi-step workflow issues stay outside what the scanner can detect.
- Authentication configuration for modern login flows is fiddly and breaks when applications change, requiring ongoing maintenance per application.
- The platform is heavy: getting value assumes someone owns configuration, scheduling and tuning as a real job.
- Check logic is vendor-controlled, so adding custom detections is limited compared with script-extensible scanners.
Who it suits
Right for a large enterprise that already runs Qualys for infrastructure and wants application scanning under the same governance, reporting and asset model. Wrong for a development-led team that wants fast, developer-owned scanning in pull requests, and wrong as a sole control where authorization logic is the main risk.
Used Qualys WAS? Recommend it under your own name and title.
Recommend this tool