Netsparker Enterprise On-Demand Change Log
Netsparker Enterprise On-Demand Update - 26th August 2021

FEATURES

  • Introduced the tagging feature for websites, website groups, and scans: While this feature has been available for Issues since March,  it is now available for scans, websites, and websites groups as well. 

 

Netsparker Enterprise On-Demand Update - 19th August 2021

This update includes changes to Internal Agents.

IMPROVEMENTS

  • Added the missing information that was not exported to YouTrack, Asana, and Github in the case of Frame Injection vulnerability.
  • Added new property to /scans/list API endpoint to distinguish between scans.
  • Added paging to auditlogs/export API endpoint.
  • Added the group by parameter to the Technology dashboard.
  • [INTERNAL AGENT] Increased the agent's polling time to 30 seconds.

FIXES

  • Fixed a bug that prevents updated scan profiles of the Scheduled Scans from being synchronized with these scheduled scans.
  • Fixed a space issue in GitLab integration that prevents integration to be completed successfully.
  • Fixed the deserialization issue that threw bad requests in some scans.
  • Fixed the issue of returning null response by removing WebsiteGroupId requirement from UserRoleWebsiteGroupMapping API endpoint.
Netsparker Enterprise On-Demand Update - 12th August 2021

This update includes changes to Internal Agents.

FEATURE

IMPROVEMENT

  • Added an option to fail Azure build for only confirmed vulnerabilities.
  • Improved the statusCode and errorMessage returned from members/deleteinvitation API endpoint on cases when the invitation is missing.
  • Changed roles/update API endpoint response status code from 201 to 200 to better comply with REST best practices.
  • Added “Override Version Vulnerability Severities” option to Scan Policy > Attacking settings.
  • Improved the error message displayed when a Website Group cannot be deleted due to it being referenced by a notification.
  • Extended the range of digits that can be entered for HOTP and TOTP configuration.
  • Improved global dashboard performance.
  • Changed the error message for members/update API endpoint for password POST requests.
  • Added a control in the UserRoleWebsiteGroupMapping API endpoint to prevent null object reference exceptions.

REMOVAL

  • Removed X-Scanner request header from the default scan policies to prevent web application firewalls from blocking scans.

FIXES

  • Fixed an error preventing NIST, DISA STIG, and ASVS classifications from appearing in the Issue details.
  • Fixed an unhandled error that occurs while deleting scans.
  • Fixed an issue where the check state is reset when the search keyword is modified on the Report Policy Editor security checklist.
  • Fixed scheduled website group scans that do not use primary scan policies.
  • Fixed an issue where multiple Common Weakness Enumeration values were being sent to Kenna Integration.
  • Fixed the incorrect API documentation of roles/listpermissions endpoint.
  • Fixed an issue where form authentication may fail because of credentials being modified when the scan profile is updated.
  • Fixed missing state field on the member API endpoint.
  • Fixed the 500 Internal Server Error message for a query string to a non-existent page.
  • [INTERNAL AGENT] Fixed an issue where a scan policy name containing invalid filename characters was causing scans to fail.
  • [INTERNAL AGENT] Fixed several scan failure issues caused by an error that occurred while trying to open the vulnerability database.
  • [INTERNAL AGENT] Fixed agent attempting to use proxy even after settings are changed.
  • [INTERNAL AGENT] Fixed an unhandled error thrown while archiving the scan data.
  • [INTERNAL AGENT] Added NoProxy option to internal agents.
Netsparker Enterprise On-Demand Update - 13th July 2021

IMPROVEMENT

FIXES

  • Fixed an issue where incorrect scan profiles and policies were used while performing group scans.
  • Fixed an issue where the State field of an issue is converted to a numeric value when the state of a revived issue is set to some other state through API.
  • Fixed an issue where an incorrect Affected Version value is reported for an out-of-date vulnerability.
  • Fixed an issue where editing a scheduled scan displays incorrect scan policy, report policy, and agent data. 
  • Fixed an issue where a custom vulnerability profile data of a report policy is not retrieved correctly when called from vulnerability/template API endpoint.
  • Fixed the missing LastLoginDate field by adding it back to member API call responses.

Netsparker Enterprise On-Demand Update - 29th June 2021

FEATURE

IMPROVEMENTS

  • Prettified the outputs printed by Azure Pipelines, GitLab and UrbanCode deploy CI/CD integrations.

  • Added support for committing changes on the tag editors with the TAB key.

  • Added Organization field to GitHub issue tracking integration.

  • Updated YouTrack issue tracker integration to use the new API.

  • Improved the performance of issues/allissues API endpoint.

  • Added alternate mail address field (if available) to the account/me API endpoint.

  • Improved Splunk integration by sending the issue updates without requiring a new scan.

  • Improved the performance of the Technology Dashboard.

  • Improved the performance of the scans/report endpoint.

  • Updated the look and feel of emails sent.

  • Added Known Issues information to issues while sending to Kenna.

  • Improved the performance of PCI scan reports.

  • Added links to CVE IDs on reports.

FIXES

  • Fixed the incorrect email displayed on the audit log when a failed login attempt is logged.

  • Fixed a bug where a team with the same name tried to be provisioned when SCIM integration is used with SSO providers.

  • Fixed the team member APIs by adding the missing CreatedAt field.

  • Fixed an issue where some users with the default View Reports rule cannot see the global dashboard page.

  • Fixed a memory leak happens while generating PDF reports.

  • Fixed a NullReferenceException thrown while calling the scans/new API endpoint.

  • Fixed an error occurs when a website which has tagged issue is deleted.

  • Fixed a page loading issue on authentication verifier.

  • Fixed the clipped user interface elements on the New User Mapping page when the page widths get narrow.

  • Fixed an issue where the Exclude Authentication Page checkbox does not get updated.

  • Fixed the overlapping logo on reports.

  • Fixed an issue where incremental scans started from CI/CD integrations are using the default profile if there are no scans performed to that website previously.

  • Fixed the Not Found error displayed while testing notifications for Azure Boards integration.

  • Fixed the empty PCI report issue.

  • Fixed random HTTP 500 error thrown from scans/report API endpoint.

  • Fixed missing agent groups when queried using agentgroups/list API endpoint.

  • Fixed an issue where old VDB results are displayed on the known issues tab.

  • Fixed a NullReferenceException.

  • Fixed connection timeout issues.

  • Fixed an issue where an exception was thrown if the agent Helper Service is set to use a different port on Linux machines.

  • Fixed an issue where the issues of a custom security check are incorrectly listed under a different vulnerability on reports.

  • Fixed a scan stuck issue.

  • Fixed scans failing on some systems while scanning TLS 1.3 websites.

Netsparker Enterprise On-Demand Update - 7th June 2021

FEATURE

  • Added support for creating Teams and Roles.
  • Added SCIM 2.0 API support for improved SSO integration which supports user and group synchronization with popular Identity Providers

IMPROVEMENT

  • Improved access control by introducing new more granular permissions
  • Improved role assignment for website groups while inviting new members

Netsparker Enterprise On-Demand Update - 20th May 2021

This update includes changes to Internal Agents.

FEATURE

  • Added Authentication Profiles feature to be able to define shared authentication once and utilize them on many scans without explicitly configuring Form Authentication for websites utilizing the same authentication procedure.

IMPROVEMENT

  • The Category selection for ServiceNow integration is made editable.
  • Added support for importing links from multiple RAML files from a ZIP file (include directive support).
  • Improved Azure AD Single Sign-On in-app help text.
  • Removed the Current Password field for admin users (logged in with SSO) while editing a member.
  • Added “Maximum URL Rewrite Signature” Scan Policy Crawling option.

FIXES

  • Fixed an error that occurs while trying to mark an issue as false positive.
  • Fixed an internal server error that happens while using the /api/1.0/scanprofiles/update API endpoint for some profiles.
  • Fixed an issue where a deleted issue tracker integration was still keeping the old issues IDs referenced.
  • [INTERNAL AGENT] Fixed an issue where the helper NHS service is unexpectedly terminated on environments with multiple agents running.
Netsparker Enterprise On-Demand Update - 11th May 2021

This update includes changes to Internal Agents.

FIX

  • [INTERNAL AGENT] Fixed an unhandled ArgumentNullException which causes some authenticated scans to fail.

Netsparker Enterprise On-Demand Update - 28th April 2021

This update includes changes to Internal Agents.

IMPROVEMENT

  • Added an option to specify a scan profile while scheduling scans through API.
  • Added support for Form Authentication Custom Scripts for cases when a Privileged Access Management integration is used.
  • Added support for 11 digit phone numbers while inviting a new member.
  • Added an option to ServiceNow integration to specify if the incident should be set to Closed when the vulnerability is fixed.
  • Added a field to specify the user’s SSO email address while creating a new team member using the API.
  • [INTERNAL AGENT] Added IgnoreSslCertificateErrors option to Docker agent.

FIXES

  • Fixed an issue with the GitLab integration script where builds were not failing when they were supposed to fail.
  • Fixed an issue where the “Add Attachment Report” section was missing while adding a new notification.
  • Fixed a mismatching type issue on /scanprofiles/list API response model.
  • Fixed an issue where a failed scan sends an excessive amount of email notifications.
  • Fixed an issue where Exclude Authentication Page configuration resets when another scan is performed.
  • [INTERNAL AGENT] Fixed agent auto-update issues.

Netsparker Enterprise On-Demand Update - 19th April 2021

This update includes changes to Internal Agents.

FEATURE

  • Added GitHub Actions CI/CD integration.
  • Added a new Scope option for Scan Groups of Websites while configuring notifications to be able to better scope notifications for web applications/APIs under a website.

IMPROVEMENT

  • Improved time zone calculations to handle new time zones.
  • Improved configuration validation error messages for Privileged Access Management integrations.

FIXES

  • Fixed validation error messages on the Email Settings page.
  • Fixed some of the swagger API validation errors reported for the REST API.
  • [INTERNAL AGENT] Fixed an agent scan stuck issue while archiving.
  • [INTERNAL AGENT] Fixed a retest problem where some issues could not be retested.
  • [INTERNAL AGENT] Fixed an agent auto-update issue.

Netsparker Enterprise On-Demand Update - 8th April 2021

This update includes changes to Internal Agents.

FEATURE

IMPROVEMENT

  • Removed the scan report selection from notification events that do not produce any reports.
  • Added account-based option to display authentication credentials on API responses.

FIXES

  • Fixed an issue where the Launch button does not get enabled on the New Scan page after you enable the IAST scanning and download the sensor files. 
  • Fixed an issue where a notification that is sent to an external email address was not displayed on the audit logs.
  • Fixed an issue where starting a PCI scan via using API could not start the scan. 
  • Fixed an issue where a new notification created via API does not add the specified integration(s) to the new notification. 
  • Fixed an issue where a team member was not created in API if the auto-generated password is enabled.
  • [INTERNAL AGENT] Fixed an issue where the custom value of FormAuthPageLoadTimeout was being overridden by its default value.

 

Netsparker Enterprise On-Demand Update - 30th March 2021

This update includes changes to Internal Agents.

FEATURE

IMPROVEMENT

  • Improved the error messages returned from the notification API endpoint.

FIXES

  • Fixed missing nodes on the sitemap tree.
  • Fixed an issue where links imported from a Burp file are incorrectly parsed as HTTP, not HTTPS.
  • [INTERNAL AGENT] Fixed an issue where an HSTS issue keeps reviving when the website is scanned again.
  • [INTERNAL AGENT] Fixed a scan failed issue that occurs during archiving scan files.
  • [INTERNAL AGENT] Fixed an issue where WSDL importing fails while trying to locate the external schema.
  • [INTERNAL AGENT] Fixed an InvalidOperationException.

Netsparker Enterprise On-Demand Update - 24th March 2021

This update includes changes to Internal Agents.

FEATURE

  • Introduced tagging support for Issues.

IMPROVEMENT

  • Added options to specify Is Confirmed and Severity values while failing Jenkins builds.
  • [INTERNAL AGENT] Added auto-update support for Linux agents.
  • [INTERNAL AGENT] Added support for TLS 1.3 protocol.
  • [INTERNAL AGENT] Updated Debian docker image to version 10.8.

FIXES

  • Fixed the “Internal Server Error While Exporting Scan” error while exporting scans from Netsparker Standard.
  • Fixed missing classification editors on report policy editor for recently added classification types.
  • [INTERNAL AGENT] Fixed an issue that causes the scan to stuck while trying to capture the website thumbnail image.

Netsparker Enterprise On-Demand Update - 17th March 2021

This update includes changes to Internal Agents.

IMPROVEMENT

  • Improved the load times of the global dashboard page.
  • [INTERNAL AGENT] Added a port configuration option for the agent helper service.

FIXES

  • Fixed an issue on /teammembers/new API endpoint where minimum password length requirement is enforced incorrectly for admin users.
  • Fixed a UI glitch where the Fixed Issues widget on the global dashboard page is clipped.
  • Fixed a user enumeration issue that exists for users where SSO is enforced.
  • Fixed an issue where updates to Custom Cookies input on Scan Profiles do not persist.
  • Fixed an issue where the Next button on Welcome Wizard is not enabled even if you select Website Groups as indicated.
  • Fixed the incorrect input label names on the HashiCorp Vault settings dialog.
  • [INTERNAL AGENT] Fixed an issue where stuck scans do not honor the Maximum Scan Duration setting.
  • [INTERNAL AGENT] Fixed an issue where an agent was creating temp files on C: drive even though it is installed in D: drive.

Netsparker Enterprise On-Demand Update - 12th March 2021

This update includes changes to Internal Agents.

FEATURE

IMPROVEMENT

  • [INTERNAL AGENT] Improved agents to reduce the number of IOPS performed.

Netsparker Enterprise On-Demand Update - 4th March 2021

This update includes changes to Internal Agents.

IMPROVEMENTS

  • Prevented deletion of system notifications.
  • Forced Browsing wordlist made editable.
  • Added tooltips displaying the full issue title on the Issues tree when the titles are clipped due to length.

FIXES

  • Fixed /notifications/ update API endpoint which was not updating recipient emails before.
  • Fixed a Scan Policy Optimizer issue where the Resource Finder settings are not captured when the selection tree is collapsed.
  • Fixed an issue where the Custom Script cannot be created when 3-Legged Authentication is selected while configuring OAuth2.
  • Fixed an issue where the ISO Compliance report cannot be exported for some of the scans.
  • [INTERNAL AGENT] Fixed runtime exceptions thrown on systems that are missing ClamAV.

Netsparker Enterprise On-Demand Update - 26th February 2021

This update includes changes to Internal Agents.

NEW FEATURES

  • Added IAST Scanning capabilities.
  • Added CyberArk Vault Privileged Access Management integration.

IMPROVEMENTS

  • HashiCorp Vault settings no more require Testing Settings as mandatory before saving the integration.
  • Added search capability to the Website Group selection drop-down on the global dashboard page.
  • Added the API endpoint option to create users that can only log in using Single Sign-on.
  • Added the last login date information to the team member API endpoint.
  • [INTERNAL AGENT] Added “Detect authentication tokens” capability for authenticated scans.

FIXES

  • Fixed an issue where the category selection widget was clipped on the Service Now integration configuration page.
  • Fixed a reporting issue where addressed issues were included on reports generated with the Exclude Addressed Issues option.
  • Fixed the “Internal Server Error While Exporting Scan” error while exporting scans from Netsparker Standard.
  • Fixed an issue where a Scan Policy used on a Scheduled Scan cannot be deleted.
  • Fixed an issue where the Single Sign-on only users were not able to access their API tokens.
  • [INTERNAL AGENT] Fixed an issue that occurs while creating the custom report policy on Linux environments.
Netsparker Enterprise On-Demand Update - 9th February 2021

IMPROVEMENTS

  • Added Scan Profile Name column to Recent Scans page.
  • Added Website URL as a filter field to Scheduled Scans page.
  • Removed encrypted authentication credentials from API responses.

FIXES

  • Fixed an issue where the scans launched from CI/CD without a Scan Profile were creating redundant Scan Groups on the Website dashboard.
  • Fixed an issue where pressing the TAB key was not committing the entered email address on email input fields.
  • Fixed an issue where some settings are not saved when you save a cloned Scan Policy for the first time.
  • Fixed an issue where the View Scan Reports and Manage Issues (Restricted) options under Scan Permission are not saved while creating new members.
  • Fixed an issue where the modified Scan Profile settings are not saved when another profile is selected from the dropdown.

Netsparker Enterprise On-Demand Update - 27th January 2021

IMPROVEMENTS

  • Improved an agent auto-update procedure to support updates for minor version changes.
  • All credential information on API responses is encrypted.
  • Prevented agent log file names to be renamed by the browser according to the user’s regional settings.

FIXES

  • Fixed an issue where the scan and report policies are not preserved while scheduling group scans.
  • Fixed several issues on the sitemap tree and improved the performance.
  • Fixed a hanging scan issue that occurs while the scan state is changing.
  • Fixed an issue where setting an already deleted scan profile name to a new scan profile gives an error.
  • Fixed the incorrect VDB version displayed on the agent.
  • Fixed an issue where Download Scan Data and Download HttpRequest Logs were not working previously.
  • Fixed an issue where an agent was not using the correct proxy settings while communicating with the web app.