Generating an audit report with a record of all servers affected by a CVE

You can generate an audit report that shows the status of each server affected by this particular CVE selected, in comma-separated value (CSV) format.

Before you begin

You must have a user profile with the View security data permission or the Manage security data permission. For more information, see Configuring roles and permissions.

Procedure

  1. Log in to WebSphere Automation.
    For more information, see Accessing the WebSphere Automation UI.
  2. Open the Security page, and click either the Servers or the CVEs tab.
    Figure 1. Example Servers page with vulnerability status of servers
    Example CVEs page showing vulnerabilities for all registered servers. Column headings include Risk level, CVE, Days Exposed, Fixed servers, Vulnerable servers, and Detection date.
    If you do not see a listing of CVEs, either no servers are registered, or you have insufficient permissions. For instructions on registering servers, see Registering a server. For more information about permissions, see Roles and permissions.
  3. Take one of the following actions to open the CVE information page:
    • On the Servers page, select a CVE link under the Unresolved CVEs column.
    • On the CVEs page, click a CVE in the CVE column.
    Figure 2. Example CVE information page with details about a particular common vulnerability or exposure that affects server inventory
    Example CVE information page with details about a particular common vulnerability or exposure that affects server inventory. Column headings include Servers, WebSphere version, Java SDK version, Hostname, Topology, Vulnerability status, Detection date, Remediation date, Days exposed, and Tags.
  4. Click Download audit report.
    In the system dialog that opens, you can open or save the audit report to your local computer.
  5. Open the audit report by using a program capable of viewing CSV files, such as a spreadsheet editor.
    The data looks similar to the following image:
    Figure 3. Viewing example audit report of record of all servers affected by a CVE in CSV format
    Example CSV file showing vulnerability status of servers. Column headings include Servers, WebSphere version, Java SDK version, Hostname, Topology, Vulnerability status, Detection date, Remediation date, Days exposed, and Tags.
    Note the column headings:
    Servers
    The name of the server. Click this column heading to toggle between grouping the servers alphanumerically by name, in reverse order, or in original (unsorted) order. You can click the name of the server to view information about the server on a dedicated page.
    WebSphere version
    The version of WebSphere Application Server or WebSphere Application Server Liberty that is used by the server. Click this column to toggle between grouping the servers numerically by version number, in reverse order, or in original (unsorted) order.
    Hostname
    The hostname of the server. Click this column heading to toggle between grouping the servers alphanumerically, in reverse order, or in original (unsorted) order.
    Topology
    The unique location information for the server. Click this column heading to toggle between grouping alphanumerically, in reverse order, or in original (unsorted) order.
    Vulnerability status
    The status of the CVE on this server, either Resolved or Unresolved. Click this column heading to toggle between alphabetical order by status, reverse alphabetical order by status, or in the original order.
    Detection date
    The date that WebSphere Automation first detected the vulnerability on a server. Click this column heading to sort between chronological order, reverse chronological order, or the original order.
    Java SDK Version
    The version of Java™ that is installed on the server.
    Days exposed
    The number of days that the server has been exposed to this vulnerability. WebSphere Automation only accounts for days that the server was exposed beginning with the date that the server was registered. If the applicable fix was installed and then uninstalled, the days during which the fix was installed are not included in the total.
    Remediation date
    The date that WebSphere Automation remediated or resolved the vulnerability on a server.
    Tags
    Tags assigned to the corresponding asset.