Where can I find the severity level of OWASP 3.2 Rules?

Derosier, Conner R 21 Reputation points
2022-12-20T21:15:17.663+00:00

Azure anomaly scoring documentation refers to severity levels for specific OWASP rules to determine whether the WAF will actually block the traffic or not. However I have been unable to find specific severity levels for specific rules either in our Azure environment or online. Can someone point me in the right direction?

Azure Web Application Firewall
0 comments No comments
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
    2022-12-20T22:34:34.687+00:00

    @Derosier, Conner R ,

    Welcome to the Microsoft Q&A forum.

    You can find the severity levels for individual OWASP 3.2 Rules listed in the corerulesets repository. For example REQUEST-911-METHOD-ENFORCEMENT rule has a severity Critical.

    272628-image.png

    Hope this answers your question. Please let me know if you have any additional questions. Thank you!

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.