AppSecNews
DAST Commercial Established

Qualys WAS

by Qualys

Web application scanning module of the Qualys platform, sharing its sensor network, asset model and reporting with infrastructure vulnerability management.

Visit qualys.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Qualys WAS in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current integration list: confirm against vendor documentation
  • API and specification import formats supported: verify

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Qualys Web Application Scanning is the application layer module of the Qualys platform. You register a web application as an asset, define its scope and authentication, and a scanner crawls it to build a map of pages, forms and parameters, then runs attack checks for injection, cross-site scripting, misconfiguration, information disclosure and transport weaknesses. The crawler executes JavaScript so script-generated navigation and single-page application views are reachable. API endpoints are covered by importing a specification such as Swagger or OpenAPI, or by supplying recorded traffic, which matters because APIs rarely expose links to crawl.

Scans run from the same sensor fleet as the rest of the platform: Qualys-hosted scanners for internet-facing applications, or virtual scanner appliances you deploy inside your own network for internal ones. The consequence is that web application findings land in the same asset inventory, tagging model and reporting engine as your host and cloud findings, which is the practical reason most organizations choose it. Findings can also be exported as rules to a web application firewall so an unpatched issue is mitigated at the edge while engineering works on a fix.

Where it fits

This sits with a central security or vulnerability management team, running on a schedule against production and staging applications across a large estate. It integrates into pipelines for release-time scanning, but full authenticated scans are too slow for per-commit use. It makes most sense where Qualys is already the system of record for vulnerabilities, so application risk does not need a separate console. You need an accurate application inventory, working authentication records and exclusion rules before results are trustworthy.

Strengths

  • Web application findings share the asset model, tagging and dashboards used for infrastructure, which removes a whole reporting integration problem.
  • Internal applications are covered by deploying scanner appliances.
  • Specification-driven API scanning reaches endpoints a crawler would never discover.
  • Compliance-oriented reporting is mature, including mappings that satisfy common audit requests.

Limitations

  • Authorization flaws, business logic abuse and multi-step workflow issues stay outside what the scanner can detect.
  • Authentication configuration for modern login flows is fiddly and breaks when applications change, requiring ongoing maintenance per application.
  • The platform is heavy: getting value assumes someone owns configuration, scheduling and tuning as a real job.
  • Check logic is vendor-controlled, so adding custom detections is limited compared with script-extensible scanners.

Who it suits

Right for a large enterprise that already runs Qualys for infrastructure and wants application scanning under the same governance, reporting and asset model. Wrong for a development-led team that wants fast, developer-owned scanning in pull requests, and wrong as a sole control where authorization logic is the main risk.

Used Qualys WAS? Recommend it under your own name and title.

Recommend this tool