- Introduction to KooGallery
-
Seller Guide
- Registration
- Joint Operations Certification and Product Access
-
Delivery Methods
- Product Release Description
- Delivery Methods
- Image Release Guide
- Releasing Professional Services
- SaaS Release Guide
- Releasing Consulting Services
- License Release Guide
- Releasing Multi-SKU Product Specifications
- Seller Management
- Product Management
- Service Supervision
- Transaction Management
- Settlement Management
- Bill Management
- Issuing Invoices to Huawei Cloud
-
FAQs
- What Enterprise Certificates Are Needed for the Registration?
- Can I Use the Same Account to Apply for Seller Registration Again After I Exit KooGallery?
- How Do I Become a KooGallery Partner?
- How Long Does It Take to Review the Registration Application?
- How Do I Release Products on KooGallery?
- How Long Does It Take to Review a Product Release Application?
- How Do I Remove a Product from the Catalog?
- When Can I Receive the Payment After a Bill Is Generated?
- When Can I Issue an Invoice for an Order?
- Is the Product Technical Support Provided by Sellers or Huawei Cloud?
- How Long Is the Validity Period of Products on KooGallery?
- How Do I Initiate an Appeal During Service Supervision?
- Can an Individual User Become a Seller on KooGallery?
- What Benefits Can I Obtain After Registering with KooGallery?
- Do I Need to Pay Deposit If I Register with KooGallery?
- How Do I Change the Company Name?
- Why Is No Bill Generated for an Order? What Are the Prerequisites for Bill Run?
- How Do I View the Sharing Ratio of a Product?
- How Do I Release a Trial SaaS Specification?
- Why Can't I Select an Image as an Image Asset?
- Reseller Guide
-
User Guide
- Support You May Need
- Huawei Cloud KooGallery Terms
- Product Purchase
- Product Use
- Service Supervision
- After-Sales Support
- Renewal Management
- Product Unsubscription
- Invoice Management
- Agencies
-
FAQs
- What Is Huawei Cloud KooGallery?
- What Software and Services Are Provided on KooGallery?
- How Do I Purchase Cloud Applications on KooGallery?
- Why Can't I Use the Pay-per-Use or Yearly/Monthly Billing Mode for Certain Products?
- How Do I View Purchased Applications?
- How Do I Request Invoices After Purchasing Products from KooGallery?
- What Do I Do If I Encounter a Problem When Using a Product?
- How Do I Renew Purchased Applications?
- What Do I Do If No Applications or Services Meet My Requirements?
- How Do I Contact a Seller?
- What Do I Do If I Cannot Contact a Seller?
- Does Huawei Cloud Support Login Through Third-Party Website?
- Common Problems About Yearly/Monthly Images
- Common Problems About Pay-per-Use Images
- How Do I Initiate an Appeal During Service Supervision?
-
Access Guide
- SaaS Access Guide V2.0 (New Products)
- SaaS Access Guide V1.0 (Existing Products)
- Automatic Deployment and Access Guide
- General Reference
Copied.
SaaS Product Security Vulnerability Scan Operation Guide and Security Specifications
Security Vulnerability Scan Operation Guide
If your SaaS products involve websites (including frontend and backend portals), ensure that your products do not contain malicious content or high-risk vulnerabilities. Scan your products before releasing them.
Procedure
- Go to the Seller Console.
- In the navigation pane, choose Application Tools > Vulnerability Scans.
- In the Basic Information area, set the name, mobile number, and email address of the contact person and click Save.
- In the Scan Services area, click Create Scan Service.
- Enter basic scan details and click Next.
- Verify the domain name ownership, select I have read and agree to the HUAWEI CLOUD Vulnerability Scan Service Agreement, and click Verify.
- Enter the website login details, confirm the details, and click Confirm.
- After the scan service is added, click Scan in the Operation column in the row containing the scan service to start it.
NOTE:
- Up to five scan services can be created.
- You cannot scan a domain name using multiple accounts or in Vulnerability Scan Service (VSS) before creating a scan service for the domain name in KooGallery. If you have created a scan task for a domain name using another account or in VSS, delete the scan task before you create a scan service for the domain name in KooGallery.
- If a product has multiple login addresses, you must create multiple scan services. Only one scan services of the same domain name can be executed at a time.
- Scan services whose domain names have not been verified cannot be edited. Scan services that are being executed cannot be edited or deleted. For scan services of a verified domain name, the domain name cannot be changed.
- After the scan is complete, you can view the scan result and report. When releasing the product, associate the scan result with the product and submit them for review.
SaaS Product Release Security Specifications
If your SaaS products involve websites (including frontend and backend portals), ensure that your products do not contain common web vulnerabilities, such as cross-site scripting (XSS), SQL injection, cross-site request forgery (CSRF), XML external entity (XXE) injection, OS injection, cross-directory access, file upload vulnerabilities, sensitive information leakage, URL redirection leakage, transport layer security (TLS) configuration defects, and web page Trojan horses. If the scan result of a product indicates that the product has a high-risk vulnerability, the product fails the scan. Fix the vulnerability before releasing the product.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot