Bulk edit host vulnerable items with patches and solutions
Recommend a patch or solution for multiple host vulnerable items concurrently using the bulk edit feature in the Security Exposure Management Workspace.
Before you begin
Role required:
- sn_vul.vulnerability_analyst, sn_vul.vulnerability_admin, or sn_vul.remediation_owner for host vulnerable items (VITs)
- sn_vul.app_sec_manager, sn_vul.app_security_champion for application vulnerable items (AVITs)
- sn_vul_container.vulnerability_analyst, sn_vul_container.vulnerability_admin, or sn_vul_container.remediation_owner for container vulnerable items (CVITs)
- sn_vulc.admin, sn_vulc.remediation_owner for configuration test results (CTRs)
About this task
In the Bulk edit modal, while adding a preferred solution and patch, you can also unassign or assign multiple host vulnerable items (VITs) to an assignment group simultaneously.
Procedure
Navigate to Workspaces > Security Exposure Management Workspace.
Note: The selected records must be in the Open, Under Investigation, or Awaiting Implementation state.
On the List page, under Host Vulnerable items, open the Active or All list.
Perform one of the following:
- Select the check box next to each item if you want to use the Only Selected Items option in the Record Selection field.
- Apply filters if you want to use the All Vulnerable Items that match filter option in the Record Selection field.
- Select the check box next to each item if you want to use the Only Selected Items option in the Record Selection field of Bulk Edit modal.
- Apply filters if you want to use the All Vulnerable Items that match filter option in the Record Selection field of Bulk Edit modal.
- Select the Bulk Edit button.
On the Bulk Edit modal, fill in the fields to recommend a patch or solution for multiple host vulnerable items.
| Field | Description |
|---|---|
| Record Selection | Records to update. Choices are:- Only Selected Items: Select this option if you want to update the records you selected using the check box. - All Vulnerable Items that match filter: Select this option if you want to update the filtered records. - Remediation Task: Select this option if you want to update the records in a remediation task and then select the desired remediation task in the Remediation task field. - Vulnerability Entry: Select this option if you want to update the records specific to a common vulnerable entry (CVE) and then select the CVE in the Vulnerability Entry field. Note:
|
| State | Change for the State of the host vulnerable items. You can add preferred solution and patch only when you choose the following states.- Do Not Update - Open - Under Investigation - Awaiting Implementation |
| Preferred Solution | Solution that is targeted for remediating all the vulnerable items selected for bulk edit. Select the change for the Preferred Solution field in the vulnerable item. Choices are from a lookup list of available preferred solutions for the VITs selected.Note:
Note: This operation doesn’t set the Preferred solution at the vulnerability entry level. Setting the Preferred solution at the vulnerability entry level would set the Preferred solution for all new VITs going forward. The bulk edit only modifies the current set of VITs.
The updated value is shown in the Vulnerable item list view. |
| Preferred patch | Patch that is targeted for remediating all the vulnerability items selected for bulk edit.Note:
|
| Unassign | All the selected items are unassigned for assignment group and remediation owner.Note:
|
| Assignment group | Assignment group for the records. All the active assignment groups appear in this field.Note: This field is deactivated when you select the Unassign check box. |
| Work notes | Text that you enter to describe the changes. |
- Select Edit.
Result
A bulk edit asynchronous job updates the selected host vulnerable items (VITs). The preferred solution and patch are added to the relevant host vulnerable items (VITs). Open a host vulnerable item, and view the preferred solution and patch in the Remediation section of the Details tab.
Parent Topic:Using bulk edit in the Security Exposure Management Workspace