Exclude the relationship between a third-party vulnerability and a solution because it is not relevant to the CI you are remediating, or it is not a concern in your environment. Manually exclude solutions using either a third-party vulnerability or solution record.

Before you begin

Role required:
  • sn_vul.write
  • sn_vul.remediation_owner

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information about managing granular roles, see Manage persona and granular roles for Vulnerability Response.

Procedure

  1. Navigate to All > Vulnerability Response > Libraries > Third-Party or Vulnerability Response > All Solutions
  2. Open a third-party vulnerability or solution record.
    1. For a third-party record: Select the Solutions related tab.
    2. For a solution record: Select the Third-Party Vulnerabilities related tab.
  3. Check the box next to each vulnerability or solution record you want to exclude.
  4. From the Actions on selected rows drop-down menu, choose Exclude.
    Third-party vulnerability record example
    The third-party or solution record no longer appears in the related tab.

    Third-party vulnerability relationships to solutions are also excluded when solutions are updated or if the nightly job is enabled.

    Third-party vulnerability relationships to solutions are excluded during the nightly scheduled job.

    Excluding third-party vulnerabilities means that the solution is no longer a factor for any preferred solution evaluation. Exclusion impacts:
    • All counts for solutions since the third-party vulnerability, vulnerable items (VIs), and, configuration items (CIs) attached to the third-party vulnerability do not count toward the solution anymore.
    • Determining the preferred solution for the third-party vulnerability and by extension the preferred solution of any attached VIs and remediation tasks containing the VI.