HP WebInspect Enterprise

Release Notes

Software version: 9.30 / September 2012

This document provides an overview of WebInspect Enterprise 9.3. It contains important information that may not be included in the manuals or in online help.  For the most recent version of this document please see the WebInspect Enterprise Landing Page.

 

WebInspect Enterprise 9.3 Features

System Requirements
Getting Started
Support
Known Problems, Limitations and Workarounds

Legal Notices

WebInspect Enterprise 9.30 Features

Software Security Center Integration

WebInspect Enterprise is a component of Software Security Center that supports managing your dynamic scanning program. The vulnerabilities discovered during dynamic testing are now integrated into Software Security Center to provide a central place to manage static and dynamic vulnerabilities. This unifies the remediation workflow for vulnerabilities regardless of whether they were found by dynamic or static testing techniques. 

Project Version Import

Onboarding dynamic applications into WebInspect Enterprise can be accomplished through Project Version Import. This feature has support for importing specific project versions that are only dynamic in nature or ensuring all project versions within SSC are imported in a single operation.

Scan Request

For organizations that want to segment their application teams from their dynamic testing teams, the scan request feature can be used to track work & needs across the two teams. In this type of environment the core responsibilities for performing scans are placed on the security team. The scan request feature allows the application teams to quickly and easily create scan requests that are monitored and fulfilled by the security team.

Publish Scans to Software Security Center

WebInspect Enterprise is the user interface that provides security professionals with the tools to confirm the comprehensiveness of a scan and the validity of the vulnerabilities it contains. Once this process has been completed, the results need to be delivered to development for remediation. To perform this action the dynamic scan can be published transferring the vulnerabilities into issues to be consumed by developers through Software Security Center.

Scan Configuration

WebInspect Enterprise provides an easy to user scan wizard that will enable individuals throughout the organization. 

Scan Templates

For a security professional to thoroughly scan a project version they may need to perform several scans. A typical example would be a site that needs the following scans to implement a comprehensive audit: one scan to determine vulnerabilities exposed to unauthenticated user, another scan to expose vulnerabilities of authenticated users and another scan to expose the vulnerabilities found in Web Services. Scan templates were created to allow users to easily manage the different settings files that are need to perform a thorough dynamic audit. Scan Templates are associated to the specific project version they are designed to attack. In this way a security professional, can ensure that products meet their security standard even when the responsibility of running the scans is distributed to the QA and or development teams.

Dynamic Scan Visualization

The visualization provided through the WebInspect desktop environment is the standard by which users can easily verify and remediate vulnerabilities. With the release of WebInspect Enterprise, HP has brought this high power interface to the Web. This will allow organizations to more readily rollout dynamic scanning efforts to individuals outside of the core security team.

Sensor Management

To scale the dynamic program within an organization requires the ability to manage a pool of scanners. Within the WebInspect Enterprise product we refer to these scanners as sensors. Using these resources, users can run scans on demand, schedule scanning to occur at appropriate times, and retest specific vulnerabilities. Special security features are provided within WebInspect Enterprise to allow administrative control over these powerful resources. The security features include but are not limited to the following: blackout periods, policy management, restricted sensor access, and ip address range validation.

System Requirements

Before installing WebInspect Enterprise version 9.30, make sure that your system meets the following requirements:

All Installations

·         Browser

§  Internet Explorer 7.0  (Minimum)

§  Internet Explorer 8.0

§  Internet Explorer 9.0 (Recommended)

§  Firefox 9.0 (Minimum)

§  Firefox 14  (Recommended)

 

·         Network

§  An active Internet connection (Recommended)

WebInspect Enterprise Server

·         Processor

§  2.5 GHz or better

 

·         RAM

§  4 GB (Minimum)

 

·         Hard Disk

§  5 GB (using remote database)

§  20 GB (using local database) (Minimum)

§  100+ GB (Recommended)

 

·         Web Server Platform

§  Microsoft IIS 6.0 (Minimum)

§  Microsoft IIS 7.0

§  Microsoft IIS 7.5 (Recommended)

 

·         CLR Platform

§  Microsoft .NET Framework 4.0

 

·         Operating System

§  Windows Server 2003 Standard SP2 (32-/64-bit)

§  Windows Server 2008 SP2  (32-/64-bit)

§  Windows Server 2008 R2 (64-bit)

 

·         Integrations

§  HP Fortify Software Security Center 3.6

WebInspect Enterprise Database

·         Processor

§  2.5 GHz or better

 

·         RAM

§  4 GB (Minimum)

 

·         Hard Disk

§  20 GB (Minimum)

§  100+ GB (Recommended)  

 

·         Operating System

§  Windows Server 2003 SP2 (32-/64-bit)

§  Windows Server 2008 SP2  (32-/64-bit)

§  Windows Server 2008 R2 (64-bit)

 

·         Supported Database

§  Microsoft SQL Server 2005 SP4

§  Microsoft SQL Server 2008 SP2

§  Microsoft SQL Server 2008 R2 (Recommended)

Note: Assessment Management Platform does not support SQL Server Express.

WebInspect Enterprise Console/Client

·         Processor

§  1.5 GHz or better

 

·         RAM

§  1 GB (Minimum)

 

·         Hard Disk

§  2 GB of free disk space

 

·         Operating System

§  Windows XP Professional SP3 (32-bit)

§  Windows Server 2003 SP2 (32-bit/64-bit)

§  Windows Server 2008 SP2 (32-/64-bit)

§  Windows Server 2008 R2 (64-bit)

§  Windows Vista SP2 (32-bit/64-bit)

§  Windows 7 (32-bit/64 bit)

 

·         Database

§  Microsoft SQL Server Express Edition 2008 SP2 (4 GB scan database limit)

§  Microsoft SQL Server Express Edition 2005 SP3 (4 GB scan database limit)

Note: Required only if you want to edit policies, compliance templates, or audit inputs

 

·         Platform

§  Silverlight Runtime v3

Note: Required only if you want to use the Scan Link Analyzer and Screenshot Attachments

WebInspect Enterprise Sensor (WebInspect 9.30)

·         Supported Operating systems:

§  Windows XP Professional SP3 (32-bit)

§  Windows Vista SP2 (32-/64-bit)

§  Windows 7 (32-/64-bit) (Recommended)

§  Windows Server 2003 SP2 (32-bit/64-bit)

§  Windows Server 2008 SP2 (32-bit/64-bit)

§  Windows Server 2008 R2 (64-bit) (Recommended)

 

·         Processor

§  1.5 GHz Single-Core (Minimum)

§  2.5 GHz Multi-Core (Recommended)

 

·         RAM

§  2 GB (Minimum)

§  4 GB (Recommended)

 

·         Hard Disk

§  10 GB (Minimum)

§  100+ GB (Recommended)

 

·         Display

§  1024 x 768 (Minimum)

§  1280 x 1024 (Recommended)

 

·         Supported Database

§  Microsoft SQL Server Express Edition 2008 R2 (10 GB scan database limit) (Minimum)

§  Microsoft SQL Server Express Edition 2008 SP2 (4 GB scan database limit)

§  Microsoft SQL Server Express Edition 2005 SP3 (4 GB scan database limit)

 

§  Microsoft SQL Server 2008 R2  (No scan database limit) (Recommended)

§  Microsoft SQL Server 2008 SP2 (No scan database limit)

§  Microsoft SQL Server 2005 SP4 (No scan database limit)

 

·         Platform

§  Microsoft .NET Framework 3.5 Service Pack 1

 

·         Browser

§  Internet Explorer 7.0 (Minimum)

§  Internet Explorer 8.0 (Recommended)

§  Mozilla Firefox 3.6 (Proxy Settings Only)

§  NOTE: For a WebInspect Enterprise environment to support Internet Protocol version 6 (IPv6), the IPv6 protocol must be deployed on each WebInspect Enterprise Console, WebInspect Enterprise Sensor, and the WebInspect Enterprise Manager

Getting Started

For easy-to-follow instructions on installing and using WebInspect Enterprise, see the Quick Start Guide.

Support

To Open a Support Case for ASC Product Issues:

Online: (Preferred method)

1.       Browse to URL http://support.openview.com/.

2.       Login. If you have not registered before, you will have to do so and provide your SAID (Service Agreement ID) number.

3.       Select your HP product and report the issue.

 

Telephone: (Voice recognition system)

1.       Call 1.800.633.3600

2.       Say “Software”

3.       Say “WebInspect” or “WebInspect Enterprise” or “QA Inspect” or “AMP”

4.       Say or Key in your SAID (Service Agreement ID) number. 

Known Problems, Limitations and Workarounds

-          When publishing dynamic results into Software Security Center, false positives will show up as issues that have been marked suppressed with an analysis value of not an Issue. If the analysis value is changed from Software Security Center, this will result in the vulnerability being marked as ignored in WebInspect Enterprise.

-          WebInspect Enterprise scan visualization does not contain a tab for Soap Request.

-          WebInspect Enterprise Scan Visualization does not support Security Scope Information.

-          If users decide to manually add FPR’s to Software Security Center, WebInspect Enterprise will not be able to manage the list appropriately. This will result in an inability to synchronize data appropriately between SSC and WebInspect Enterprise.

-          Scan Configuration details within WebInspect Enterprise do not support Restful Rules cannot be viewed are added.

-          Moving a published scan from one Project Version to another in WebInspect Enterprise will result in the following side effect. Any issues that were not found by any other previously published scan will be marked fixed upon the next publish event for that project version.

-          Deleting a screenshot in SSC does not propagate back to WebInspect Enterprise. If you wish this to propagate you must add, remove or modify a comment on the vulnerability.

Legal Notices

©Copyright 2004-2012 Hewlett-Packard Development Company, L.P.

Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. The information contained herein is subject to change without notice.