Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create penetration test findings based on assessment requests (prior to v19.0)

Create penetration test findings based on the penetration test assessment request. These findings are manually-created Application Vulnerability Items (AVIs).

Before you begin

Role required: Ethical Hacker

Procedure

  1. Navigate to All > Self-Service > Service Catalog > Services > Penetration Test Assessment Requests.

  2. To create an AVI for a penetration test assessment request, select the relevant request.

  3. In the Application Vulnerable Items section, select New.

  4. On the form, fill in the fields.

FieldDescription
NumberAutomatically generated AVI identifier for this record.
Assessment requestPenetration test assessment request with which this AVI is associated.
VulnerabilityVulnerability selected from the Vulnerability Entries table using the search option.
Risk ratingQuantified Risk Score separating vulnerable items into Critical, High, Medium, Low, and None. For more information on risk ratings, see Calculate risk in Application Vulnerability Response automatically.Starting from V16.1, by default the value is the same as the severity of the vulnerability.
Impacts any compliance program?Confirms whether there is an impact on any compliance program. Choices are Yes and No.
List of compliance programs impactedThis field is displayed when then value of the 'Impacts any compliance program' field is set to Yes. Lists the impacted compliance programs.
Planned release/fix versionRelease by when the penetration test findings must be resolved.
StateDefault value is Open when the AVI is created. See Application Vulnerable Item (AVI) states for more information on how states are mapped.
Assignment groupGroup selected to work on this AVI. Can be manually added or edited by an App-Sec Manager.
Assigned toIndividual from the selected assignment group that works on this AVI. Can be manually added or edited by an App-Sec Manager.
Remediation targetDate by which the AVIs must be remediated, since first identified. This field only appears when applicable.For more information on remediation targets, see Automate remediation target tracking in Application Vulnerability Response.
CreatedTimestamp when the application vulnerable item \(AVI\) was created.
UpdatedTimestamp when the application vulnerable item \(AVI\) was updated.
Opened byUser who created this penetration test finding.
Security team contactPoint of contact in the ethical hacking team.
Short descriptionBrief explanation of the penetration test finding.
Details
Technical detailsTechnical details of the penetration test finding.
ImpactAssessment of the impact of the penetration test finding.
Steps to reproduceDocument the steps to reproduce and review the penetration test finding.
RecommendationRecord the recommended actions in this field.
Notes
Work notesAdd notes to communicate information about state transitions and other field updates.
V16.1: Affected URLsFurther information related to the affected URLs.
V16.1: Affected parametersFurther information related to the affected parameters.
V16.1: Affected functionalitiesFurther information related to the affected functionalities.
  1. To save the form, select Submit.