Knowledge base API v2

Version 4

    Hello All,

     

    If you've been using the knowledgebase_download.php API v1 (KBX v1), we recommend that you convert your API request to the equivalent knowledge base API v2 (KBX v2). While KBX v1 will still be available in the future to maintain backward compatibility, new feature the the KBX will be added to v2.

    With KBC b2, you can:

    • Do a differential update : no need anymore to download everyday the 30MB+, you can only get the new or updated QIDs !

    Example: https://qualysapi.qualys.com/api/2.0/fo/knowledge_base/vuln/?action=list&details=All&last_modified_after=2011-09-01

    • Get addional details about the vulnerabilities such as the full CVSS metrics and sub-metrics, the published date and type of discovery (list of the updates below)

     

    NEW:                    <PUBLISHED_DATETIME>

    UPDATED:          <BUGTRAQ_ID_LIST> simplified to <BUGTRAQ_LIST>

    UPDATED:          <BUGTRAQ_ID> simplified to <BUGTRAQ>

    UPDATED:          <CVE_ID_LIST> simplified to <CVE_LIST>

    UPDATED:          <CVE_ID> simplified to <CVE>

    UPDATED:          <EXPLOITABILITY> simplified to <EXPLOITS>

    REMOVED:          <CVSS_BASE>

    REMOVED:          <CVSS_TEMPORAL>

    NEW:                    <CVSS>

    NEW:              CVSS -> <BASE>

    NEW:              CVSS -> <TEMPORAL>

    NEW:              CVSS -> <ACCESS>

    NEW:              CVSS -> ACCESS -> <VECTOR>

    NEW:              CVSS -> ACCESS -> <COMPLEXITY>

    NEW:              CVSS -> <IMPACT>

    NEW:              CVSS -> IMPACT -> <CONFIDENTIALITY>

    NEW:              CVSS -> IMPACT -> <INTEGRITY>

    NEW:              CVSS -> IMPACT -> <AVAILABILITY>

    NEW:              CVSS -> <AUTHENTICATION>

    NEW:              CVSS -> <EXPLOITABILITY>

    NEW:              CVSS -> <REMEDIATION_LEVEL>

    NEW:              CVSS -> <REPORT_CONFIDENCE>

    NEW:                    <DISCOVERY>

    NEW:                    DISCOVERY -> <REMOTE>

    NEW:                    DISCOVERY -> <AUTH_TYPE_LIST>

    NEW:                    DISCOVERY -> AUTH_TYPE_LIST -> <AUTH_TYPE>

     

    Please note that you need to ebable CVSS for your subscription first if you want to get the CVSS metrics. As a manager go to "Reports --> Setup --> CVSS -->  Enable CVSS" and click "save".

    Screen Shot 2012-01-11 at 09.20.08 .png

     

    Attached you'll find the two version of the QID 90464

     

    Please let me know if you have any question,

    Thanks,

    Eric

     

    This document was generated from the following discussion: New knowledge base API