- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 08:05 AM
Can we scan CIs in my CMDB without Qualys or any thrid party vulnerability scanner? Just with my vulnerability base application?
Solved! Go to Solution.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 08:33 AM
That is an excellent question. You can have the NVD and CWE scan your CI. The catch is that you must have SAM Pro purchased for your instance in order to perform this task.
https://docs.servicenow.com/bundle/london-security-management/page/product/vulnerability-response/concept/sam-nvd-vul-detection.html
I confirmed this in my personal instance. Also, my org stumbled on to this requirement in our instance. It helps us justify the need for Software Asset Management.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 09:01 AM
I have to admit that I had missed that functionality before now. I'm interested to see how well this works in practice-- if you reconfigure a device to remediate a vulnerability, but there are no changes to the software versions, will it still show up? (aka- become a false positive.)
Otherwise, for clients with both SAM and VR, this is one more layer of assurance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 09:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 09:24 AM
Which scanner are you using currently in your Instance of client?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 09:42 AM
I'm actively working a Tenable implementation at one client, and have two Rapid7s going as well. (We did a Qualys implementation in 2017 also.) None of these clients use SAM, though. We are trying to change that, though. 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎11-29-2018 09:49 AM