Generic framework to ingest data from any solution vendor

  • Release version: Xanadu
  • Updated August 1, 2024
  • 1 minute to read
  • A generic framework for solution intelligence integration is available to support ingestion of data in different file formats from solution vendors. These formats speed up information exchange and processing and facilitate the sharing of critical security-related information in a standardized reporting format.

    The supported file formats are:
    Common Vulnerability Reporting Framework (CVRF)
    The Common Vulnerability Reporting Framework (CVRF) is an XML-based language. Major vendors such as Oracle, Red Hat, Cisco, and Microsoft support the CVRF format.
    Common Security Advisory Framework (CSAF)
    The Common Security Advisory Framework (CSAF) is an open-source standard that provides JSON-based structured, machine-readable security advisories. Major vendors such as Siemens, Red Hat, Hitachi, and Schneider support the CSAF format.
    The CVRF or CSAF supported solution management includes the following key features:
    • Configuration through Setup Assistant
    • Support of importing CVRF or CSAF data through file import
    • Support of importing CVRF or CSAF data through CVRF or CSAF URL
    • Support of importing CVRF or CSAF data through advisories
    • Mapping of solutions with related vulnerabilities

    The Vulnerability Response plugin takes care of updating the metrics statuses of the created solution.

    SUSE Solution Integration: This feature enables automated ingestion of remediation solutions from third-party vendor SUSE through CSAF. The purpose is to streamline vulnerability response by importing vendor-provided solution advisories, parsing them, and creating actionable solution records within the platform. This ensures that security teams have quick access to accurate and up-to-date remediation guidance for vulnerabilities affecting SUSE products.  
    Table 1.
    Name Details
    SUSE Solution Integration
    • Activation: Integration is activated upon solution management installation, you can activate as per requirement.
    • URL-based: The integration pulls CSAF IDs from a provided URL endpoint.
    • Pre-Configured URL: The URL is preconfigured in setup assistantunder Common Security Advisory Framework.

    For more information on how to configure the solution providers, see Configure vulnerability solution providers.