Research asset vulnerabilities

The Vulnerabilities pane on the Asset Profile page displays a list of discovered vulnerabilities for the asset.

About this task

You can double-click the vulnerability to display more vulnerability details.

The Research Vulnerability Details window provides the following details:

Parameter Description
Vulnerability ID Specifies the ID of the vulnerability. The Vuln ID is a unique identifier that is generated by Vulnerability Information System (VIS).
Published Date Specifies the date on which the vulnerability details were published on the OSVDB.
Name Specifies the name of the vulnerability.
Assets Specifies the number of assets in your network that have this vulnerability. Click the link to view the list of assets.
Assets, including exceptions Specifies the number of assets in your network that have vulnerability exceptions. Click the link to view the list of assets.
CVE

Specifies the CVE identifier for the vulnerability. CVE identifiers are provided by the NVDB.

Click the link to obtain more information. When you click the link, the NVDB website is displayed in a new browser window.

xforce

Specifies the X-Force identifier for the vulnerability.

Click the link to obtain more information. When you click the link, the IBM Internet Security Systems website is displayed in a new browser window.

OSVDB

Specifies the OSVDB identifier for the vulnerability.

Click the link to obtain more information. When you click the link, the OSVDB website is displayed in a new browser window.

Plugin Details

Specifies the QRadar Vulnerability Manager ID.

Click the link to view Oval Definitions, Windows Knowledge Base entries, or UNIX advisories for the vulnerability.

This feature provides information on how QRadar Vulnerability Manager checks for vulnerability details during a patch scan. You can use it to identify why a vulnerability was raised on an asset or why it was not.

CVSS Score Base

Displays the aggregate Common Vulnerability Scoring System (CVSS) score of the vulnerabilities on this asset. A CVSS score is an assessment metric for the severity of a vulnerability. You can use CVSS scores to measure how much concern a vulnerability warrants in comparison to other vulnerabilities.

The CVSS score is calculated using the following user-defined parameters:

  • Collateral Damage Potential
  • Confidentiality Requirement
  • Availability Requirement
  • Integrity Requirement

For more information about how to configure these parameters, see Adding or editing an asset profile.

For more information about CVSS, see http://www.first.org/cvss/ .

Impact Displays the type of harm or damage that can be expected if this vulnerability is exploited.
CVSS Base Metrics

Displays the metrics that are used to calculate the CVSS base score, including:

  • Access Vector
  • Access complexity
  • Authentication
  • Confidentiality impact
  • Integrity impact
  • Availability impact
Description Specifies a description of the detected vulnerability. This value is only available when your system integrates VA tools.
Concern Specifies the effects that the vulnerability can have on your network.
Solution Follow the instructions that are provided to resolve the vulnerability.
Virtual Patching Displays virtual patch information that is associated with this vulnerability, if available. A virtual patch is a short-term mitigation solution for a recently discovered vulnerability. This information is derived from Intrusion Protection System (IPS) events. If you want to install the virtual patch, see your IPS vendor information.
Reference

Displays a list of external references, including:

  • Reference Type - Specifies the type of reference that is listed, such as an advisory URL or mail post list.
  • URL - Specifies the URL that you can click to view the reference.

Click the link to obtain more information. When you click the link, the external resource is displayed in a new browser window.

Products

Displays a list of products that are associated with this vulnerability.

  • Vendor - Specifies the vendor of the product.
  • Product - Specifies the product name.
  • Version - Specifies the version number of the product.

Procedure

  1. Click the Assets tab.
  2. On the navigation menu, click Asset Profiles .
  3. Select an asset profile.
  4. In the Vulnerabilities pane, click the ID or Vulnerability parameter value for the vulnerability you want to investigate.