Viewing Vulnerability Management

Upon accessing the module, you see the main grid, which provides an overview of all tracked vulnerabilities:

Column Details:

Viewing a Product

Software Versions

  1. Click the Name of the desired product in the Vulnerability Management page.

  1. This opens the Software/Product Version View, listing:

    • CPE Uri for each version.

    • Title (version description).

    • One row per version known in the NVD.

If a product has only a single version listed, clicking on the product name will take you directly to the list of associated CVEs for that version.

CVEs for a Specific Version

  1. Open the Version’s Vulnerability List

    • Click a version row to view its associated CVEs.

  1. Vulnerability Details List

    • Title: The version description of a software/product.

    • CPE URI: Common Platform Enumeration Uniform Resource Identifier uniquely identifies software products, their versions, and sometimes their platforms or vendors.

    • CVE ID: CVE ID (Common Vulnerabilities and Exposures Identifier) is a unique identifier assigned to a specific security vulnerability.

    • Metric V2 Severity and Metric V3 Severity: Color-coded Severity,

      • HIGH = yellow

      • MEDIUM = orange

      • Critical = Red

      • Low = Green

    • Description: Description of the vulnerability.

    • Last Modified Date: The date the vulnerability (CVE) first appeared publicly in the National Vulnerability Database (NVD), marking its initial disclosure to the public and security community.

    • Published Date: The most recent date when any information about the vulnerability was updated in the NVD.

      • You can filter vulnerabilities by their published year using the Published Year dropdown. This allows you to quickly view vulnerabilities that were published in a specific year.

  2. View Full CVE Details

    • Click the CVE ID to see:

      • Full description.

      • Reference links.

      • Known affected software configurations.

      • Reference Links: External resources for remediation.

See Which Assets Are Affected

You can identify impacted assets (CIs) in two ways:

Option 1 — From the Vulnerability page

Option 2 — From the CMDB

When searching for an Asset ID in the CMDB, it’s important to understand the distinction between main assets and components:

Option 3- From the BSM View