Tenable.io web application scanning asset and vulnerabilities import in ServiceNow are not working

shallumittal
Tera Contributor

Dear Experts,

We are facing an issue in web scanning import from Tenable.io into ServiceNow for #Vulnerability Response implementation.

Connection between the Tenable.io and ServiceNow is successful. However, in ServiceNow we are receiving only Nessus agent asset data, Not getting any asset or vulnerabilities for web application scanning. (Source = web scanning)

 

Kindly advise.

 

Thanks!

12 REPLIES 12

stevejarman
Giga Guru

Hi - did you ever get to the bottom of this? We are facing the same issue currently. I assume it's just a shortcoming in the plugin - i.e. it simply doesn't import data from the WAS module in Tenable?

robbav
Tera Contributor

You have probably discovered this already, but for others: as of now tenable doesn't yet expose webapp vulnerabilities, so it is not currently possible to import webapp vulnerabilities (Source = web scanning) by querying a tenable API.

 

 

Crystal
Tera Contributor

I came here looking for more information to see if this was possible or not. Our organization wants this feature - sad to hear this news.

robbav
Tera Contributor

Good news (of sorts)!
tenable have created an API to get Web App scans out of tenable.io, this is now GA.
ServiceNow have confirmed theyre releasing an app to query the API. No date given.