Viewing Security Vulnerability Alerts

FlexNet Code Insight 2019 R1

When security vulnerability alerts are generated as part of an Electronic Update, email notifications are sent to the project owners. In addition to these email alerts, security vulnerability alerts can be viewed via the Project Inventory page.

To view security vulnerability alerts, do the following:

1. Navigate to the Project Inventory page. The page contains the following fields that inform you of alerts:
Alerts— Displays the number of open and closed alerts for the selected inventory item.
Open Alert Notice—Displays the number of open alerts for the current inventory item.

Note • If there are no open security vulnerability alerts, the notice will not be shown.

2. Click the hyperlink (x open alerts) in one of the alert fields. The Alerts dialog appears.
3. View the following information:
Type—This column displays the alert type. In this release, only New Vulnerability alerts are available.
Date—The date that the alert was created.
Priority—The priority of the alert, shown as High, Medium, or Low. The priority defaults to the severity of the security vulnerability for the alert.
Status—The status, Open or Closed, of the alert in FlexNet Code Insight. Alerts that have been closed have an icon () to further identify them.
Details—This column contains the following information about the alert:
Source—Where the vulnerability was found, National Vulnerability Database (NVD) or Secunia Advisories (as published by the Secunia Research team from Flexera).
ID—The identification number of the vulnerability associated with the Common Vulnerabilities and Exposures (CVE). If this is a hyperlinked field, click it to go to the actual entry for the vulnerability on the advisory website.
CVSS Score—The score of the vulnerability based on the Common Vulnerability Scoring System (CVSS). The values of the CVSS score range from 0.1 to 10, with 10 being the most serious. If the vulnerability has no score, the value is N/A.
Description—The description of the vulnerability as displayed in the National Vulnerability Database.
4. (Optional) To change the display based on the status of the vulnerability, select one of the following filters from the pulldown menu:
Show Open Alerts—Display only open alerts.
Show Closed Alerts—Display only closed alerts.
Show All Alerts—Display both closed and open alerts. This option will only be available if more than one alert is available.
5. When you finish viewing alert information, click Close to return to the Project Inventory page.