Pre-requisites

Roles and Permissions for Available APIs

Refer below to find the API URLs for Knowledgebase, Host Detection and WAS Finding with their required roles and permissions.

Knowledgebase

/api/2.0/fo/knowledge_base/vuln/?action=list

Role   

Permissions

Manager, Unit Manager, Scanner, Reader   

Download vulnerability data from the KnowledgeBase.

Auditor   

No permission to download vulnerability data from the KnowledgeBase.

Host Detections

/api/2.0/fo/asset/host/vm/detection/

Role   

Permissions

Managers   

View all VM scanned hosts in subscription

Unit Managers   

View VM scanned hosts in the user’s assigned business unit.

Scanners and Readers   

View VM scanned hosts in the user’s account.

Auditors   

Have no permission to view VM scanned hosts.

Refer to Qualys API (VM, PC) User Guide for more.

WAS Findings

/qps/rest/3.0/search/was/finding   

Permissions required

User account must enable WAS module with the permission -

Access Permission “API Access”.

Refer to Qualys API (WAS) User Guide for more.