Note:
This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.
If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the KB2556844 and documentation before proceeding.
If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
The Vulnerability Response Patch Orchestration application correlates patches with vulnerable items and provides visibility into the missing patches for your critical vulnerable items and assets.
Vulnerability Response Patch Orchestration is a dependent plugin for Patch Orchestration integrations.
The key features include:
- View missing patches on your assets.
- View patch details about the supersedence, SLA, and status of deployments.
- Select the preferred patch that matches the vulnerability of the vulnerable item.
- States of vulnerable items automatically transition from "Open" to "Awaiting Implementation" when a preferred patch exists.
- View patch progress information at the remediation task level that is available in the Vulnerability Response Workspaces and in the classic UI.
New
- Admins can link Patch Requests to Change Requests, enabling automatic approval or rejection of Patch Requests based on Change Request state transitions. The workflow supports both backend and UI integration, allowing Patch Requests to be created and managed directly from Change Requests.
- The Patch Deployment section is now available in the Change Request creation modal, enabling users to schedule and deploy patches as part of Change Request processes.
Changed
- The Patch Deployment section in the Change Request modal now adapts to installed applications. If both vulnerability response and patch orchestration modules are installed, the Patch Deployment section is visible; otherwise, it is hidden to streamline the user interface.
- Patch Request state labels have been updated for clarity. The "change_pending" state is now labeled as "Awaiting Change Approval" to better reflect its purpose.
- Patch Request approval logic has been revised for Change Request state mapping. The system now accurately tracks when a Change Request reaches the Implement state, ensuring Patch Requests are approved or rejected reliably.
Removed
- The Remediation Task state-based Patch Request sync workflow has been temporarily removed. This workflow is no longer active while cancellation behavior is redesigned and will be reintroduced in a future release.
-
The Vulnerability Response application and its dependent plugins must be installed and activated.
-
The following dependent plugins for Vulnerability Response must be activated: om.snc.vul_dep plugin for Vulnerability Response Dependencies om.snc.change_management plugin "Change Management - Core" is required for change management with Vulnerability Response.
-
The following Security Operations applications must be installed and activated. Click the View Dependencies and Licensing Requirements link in the right panel for more information about these applications.
- Security Integration Framework
- Security Support Common
- Security Support Orchestration
- Vulnerability Solution Management
-
Roles required:
- System Admin (admin) for installation of applications
- Vulnerability Admin (sn_vul.vulnerability_admin) for VR configuration
- sn_vul_patch_orch.read_patch and sn_vul_patch_orch.configure_patch for configuring and viewing the patches