A security team is conducting a vulnerability assessment of an internal web application. They discover a critical SQL injection vulnerability that could allow an attacker to bypass authentication. Which of the following is the MOST appropriate immediate action to take after confirming the vulnerability?
- ASchedule a penetration test to exploit the vulnerability further.
- BImplement a Web Application Firewall (WAF) rule to block common SQL injection patterns.
- CDocument the finding and assign a severity rating to it.
- DNotify the development team to fix the vulnerability in the next release cycle.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement a Web Application Firewall (WAF) rule to block common SQL injection patterns.
Implementing a WAF rule is the most appropriate immediate action because it provides an immediate, albeit temporary, mitigation for the critical vulnerability, protecting the application while a permanent fix is developed and deployed by the development team. This is a common practice for critical vulnerabilities discovered in production.
Why the other options are wrong
- A. Exploiting it further is not an immediate protective action; the goal is to stop the vulnerability from being exploited by an attacker.
- C. Documenting and rating is part of the process but does not provide immediate protection against exploitation.
- D. Notifying the development team for a fix is necessary, but 'next release cycle' implies a delay, leaving the critical vulnerability exposed in the interim.
Virtual Patching (WAF)
Virtual patching, often implemented via a Web Application Firewall (WAF), is a security measure that shields a vulnerable application from attacks by intercepting and inspecting traffic, blocking malicious requests without modifying the application's source code.
- Provides immediate protection for known vulnerabilities.
- Does not require changes to the application code.
- Acts as an interim solution until a permanent fix is deployed.
- Effective against common web application attacks like SQL Injection and XSS.
Memory trick: When a critical vulnerability is found, patch it fast, then fix it right.