WAFs - Exceptions

Partially update an Exception for a Web Application Firewall (WAF)

Update one or more fields of an existing exception for a WAF without affecting other fields.

patch/workspace/wafs/{waf_id}/exceptions/{exception_id}

Path parameters

exception_idinteger required

A unique integer value identifying the WAF exception.

waf_idinteger required

A unique integer value identifying the WAF.

Request body

rule_id0 | 1 | 2 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 1000 | 1001 | 1002 | 1003 | 1004 | 1005 | 1006 | 1007 | 1008 | 1009 | 1010 | 1011 | 1013 | 1015 | 1016 | 1017 | 1100 | 1101 | 1102 | 1103 | 1104 | 1105 | 1106 | 1107 | 1108 | 1109 | 1110 | 1198 | 1199 | 1200 | 1202 | 1203 | 1204 | 1205 | 1206 | 1207 | 1208 | 1209 | 1210 | 1302 | 1303 | 1310 | 1311 | 1312 | 1314 | 1315 | 1400 | 1401 | 1402 | 1500 | 2001
  • 0 - All Rules
  • 1 - Validation of protocol compliance: weird request, unable to parse
  • 2 - Request too big, stored on disk and not parsed
  • 10 - Validation of protocol compliance: invalid HEX encoding (null bytes)
  • 11 - Validation of protocol compliance: missing or unknown Content-Type header in a POST (this rule applies only to Request Body match zone)
  • 12 - Validation of protocol compliance: invalid formatted URL
  • 13 - Validation of protocol compliance: invalid POST format
  • 14 - Validation of protocol compliance: invalid POST boundary
  • 15 - Validation of protocol compliance: invalid JSON
  • 16 - Validation of protocol compliance: POST with no body
  • 17 - Possible SQL Injection attack: validation with libinjection_sql
  • 18 - Possible XSS attack: validation with libinjection_xss
  • 1000 - Possible SQL Injection attack: SQL keywords found in Body, Path, Query String or Cookies
  • 1001 - Possible SQL Injection or XSS attack: double quote (") found in Body, Path, Query String or Cookies
  • 1002 - Possible SQL Injection attack: possible hex encoding (0x) found in Body, Path, Query String or Cookies
  • 1003 - Possible SQL Injection attack: MySQL comment (/*) found in Body, Path, Query String or Cookies
  • 1004 - Possible SQL Injection attack: MySQL comment (*​/) found in Body, Path, Query String or Cookies
  • 1005 - Possible SQL Injection attack: MySQL keyword (|) found in Body, Path, Query String or Cookies
  • 1006 - Possible SQL Injection attack: MySQL keyword (&&) found in Body, Path, Query String or Cookies
  • 1007 - Possible SQL Injection attack: MySQL comment (--) found in Body, Path, Query String or Cookies
  • 1008 - Possible SQL Injection or XSS attack: semicolon (;) found in Body, Path or Query String
  • 1009 - Possible SQL Injection attack: equal sign (=) found in Body or Query String
  • 1010 - Possible SQL Injection or XSS attack: open parenthesis [(] found in Body, Path, Query String or Cookies
  • 1011 - Possible SQL Injection or XSS attack: close parenthesis [)] found in Body, Path, Query String or Cookies
  • 1013 - Possible SQL Injection or XSS attack: apostrophe (') found in Body, Path, Query String or Cookies
  • 1015 - Possible SQL Injection attack: comma (,) found in Body, Path, Query String or Cookies
  • 1016 - Possible SQL Injection attack: MySQL comment (#) found in Body, Path, Query String or Cookies
  • 1017 - Possible SQL Injection attack: double at sign (@@) found in Body, Path, Query String or Cookies
  • 1100 - Possible RFI attack: scheme "http://" found in Body, Query String or Cookies
  • 1101 - Possible RFI attack: scheme "https://" found in Body, Query String or Cookies
  • 1102 - Possible RFI attack: scheme "ftp://" found in Body, Query String or Cookies
  • 1103 - Possible RFI attack: scheme "php://" found in Body, Query String or Cookies
  • 1104 - Possible RFI attack: scheme "sftp://" found in Body, Query String or Cookies
  • 1105 - Possible RFI attack: scheme "zlib://" found in Body, Query String or Cookies
  • 1106 - Possible RFI attack: scheme "data://" found in Body, Query String or Cookies
  • 1107 - Possible RFI attack: scheme "glob://" found in Body, Query String or Cookies
  • 1108 - Possible RFI attack: scheme "phar://" found in Body, Query String or Cookies
  • 1109 - Possible RFI attack: scheme "file://" found in Body, Query String or Cookies
  • 1110 - Possible RFI attack: scheme "gopher://" found in Body, Query String or Cookies
  • 1198 - Possible RCE attack: validation with log4j (Log4Shell) in HEADERS_VAR
  • 1199 - Possible RCE attack: validation with log4j (Log4Shell) in Body, Path, Query String, Headers or Cookies
  • 1200 - Possible Directory Traversal attack: double dot (..) found in Body, Path, Query String or Cookies
  • 1202 - Possible Directory Traversal attack: obvious probe (/etc/passwd) found in Body, Path, Query String or Cookies
  • 1203 - Possible Directory Traversal attack: obvious windows path (c:) found in Body, Path, Query String or Cookies
  • 1204 - Possible Directory Traversal attack: obvious probe (cmd.exe) found in Body, Path, Query String or Cookies
  • 1205 - Possible Directory Traversal attack: backslash () found in Body, Path, Query String or Cookies
  • 1206 - Possible Directory Traversal attack: slash (/) found in Body, Query String or Cookies
  • 1207 - Possible Directory Traversal attack: obvious path probe (/..;/) found in Body, Query String or Cookies
  • 1208 - Possible Directory Traversal attack: obvious path probe (/.;/) found in Body, Query String or Cookies
  • 1209 - Possible Directory Traversal attack: obvious path probe (/.%2e/) found in Body, Query String or Cookies
  • 1210 - Possible Directory Traversal attack: obvious path probe (/%2e./) found in Body, Query String or Cookies
  • 1302 - Possible XSS attack: html open tag (<) found in Body, Path, Query String or Cookies
  • 1303 - Possible XSS attack: html close tag (>) found in Body, Path, Query String or Cookies
  • 1310 - Possible XSS attack: open square bracket ([) found in Body, Path, Query String or Cookies
  • 1311 - Possible XSS attack: close square bracket (]) found in Body, Path, Query String or Cookies
  • 1312 - Possible XSS attack: tilde character (~) found in Body, Path, Query String or Cookies
  • 1314 - Possible XSS attack: back quote ( `) found in Body, Path, Query String or Cookies
  • 1315 - Possible XSS attack: double encoding (%[2|3]) found in Body, Path, Query String or Cookies
  • 1400 - Possible trick to evade protection: UTF7/8 encoding (&#) found in Body, Path, Query String or Cookies
  • 1401 - Possible trick to evade protection: MS encoding (%U) found in Body, Path, Query String or Cookies
  • 1402 - Possible trick to evade protection: encoded chars (%20-%3F) found in Body, Query String or Cookies
  • 1500 - Possible File Upload attempt: asp/php (.ph, .asp or .ht) found in filename in a multipart POST containing a file
  • 2001 - Possible CVE-2022-22965 attack: Tomcat Pipeline Context tampering
namestring
pathstring nullable
operator'regex' | 'contains'
  • regex - regex
  • contains - contains
activeboolean

Response

WAF rule partially updated successfully.

statestring

Changes

No recorded changes to this endpoint across all 1 revision of this API.