Can we manually create a vulnerability?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎01-30-2025 01:25 PM
Is it possible to create a vulnerability manually through the UI? Not a VIT, rather an entry under "Libraries" in either NVD, CWE or third-party? Not seeing a "NEW" button out-of-the-box, or in any of the other Libraries for that matter. This is within the Vulnerability Response module, NOT the Application Vulnerability Response module. Context is below:
I am manually creating VITs based on a findings report from a penetration testing team. I wish to link a vulnerability to the VIT, but the only options are those pulled in from third-party libraries, NVD, CVE, etc. I wish to create manual vulnerabilities labeled as: 2025 Q1 Pentest: Finding #. This way, I can still populate the 'vulnerability" tab of the VIT with all the information the remediation teams need to resolve the finding. By populating a vulnerability into these manually created VITs, I can also use this information to feed the logic conditions of my vulnerability calculator rules which determine Risk Score and Risk Rating.
If anyone knows how to accomplish this, or alternatives to otherwise feed penetration test findings (non-app related) into assignable Vulnerable Items (VITs) or Remediation Tasks (VULs), please let me know.
Thank You
- Labels:
-
Best Practices
-
Vulnerability Response
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎02-25-2025 12:45 PM
The manual upload option seems quite viable, but even this runs into a similar problem - a vulnerability ID is mandatory in order to upload it. And although you can manually input severity, there is no input for risk rating