Libraries
Monitor the security status of the libraries that your applications use.
The Libraries tab provides a centralized view of the software libraries integrated into your applications, helping you identify and prioritize remediation for those with known security vulnerabilities. By visualizing the top 10 libraries with the highest count of critical and high-severity vulnerabilities, you can quickly assess your security risk profile. The detailed list view allows you to drill down into specific library metrics, including CVSS scores, and access direct links to recommended version upgrades to streamline your security patching workflow.
Dashboards
The dashboards section offers a high-level, visual overview of your application security posture, aggregating critical telemetry data into actionable insights. This dashboard displays the top 10 libraries with the highest count of critical or high vulnerabilities, allowing you to monitor real-time security trends, track the lifecycle of vulnerabilities across your services, and evaluate the effectiveness of your remediation efforts. By leveraging these visual tools, you can maintain continuous visibility into your environment’s security health and identify emerging threats before they impact your production systems.
Library list
The library list displays all libraries that are in use by the services you select. This list helps you to understand the risks introduced by the use of those libraries. Filter the list by Status, CVSS Score, EPSS, Library type.
| Cisco Security Risk Score is deprecated. |
|---|
|
The Cisco Security Risk Score column in the vulnerability list, vulnerability details, library list, and library details has been deprecated. Cisco Security Risk Score metrics were from an integration with Cisco Vulnerabilities Management (formerly Kenna Security), which is now at end-of-sale. This metric has been replaced by the Exploit Prediction Scoring System (EPSS), which provides both a probability of vulnerability exploitation in the wild and a percentile ranking relative to all known EPSS scores. EPSS is updated daily. |
List columns:
-
Library: Name of the library.
-
Status: Current state of the library (confirmed, detected, downgraded, fixed, ignored, not vulnerable, removed, upgraded).
-
Environment: The value you specified in your Secure Application agent
otel.resource.attributesparameter or in theOTEL_RESOURCE_ATTRIBUTEenvironment variable. -
Service: Name of the service using this library.
-
CVSS Score: Common Vulnerability Scoring System (CVSS) score v3. The CVSS is a numeric value from 0.0 to 10.0 that represents the severity of a vulnerability. This open industry standard helps organizations assess and prioritize remediation efforts based on principal characteristics like exploitability and potential impact. A higher score indicates a more severe vulnerability.
-
EPSS: The Exploit Prediction Scoring System (EPSS) provides both a probability of vulnerability exploitation in the wild and a percentile ranking relative to all known EPSS scores. EPSS is updated daily.
-
Associated vulnerabilities
-
Recommended action: Any remediation that is available for the library.
Library details
The library details page provides a comprehensive view of a specific library's security posture, helping you understand the vulnerabilities associated with it and the steps required to remediate them.
Library details are organized into the following sections:
-
Highest CVSS Score Since Past Week: Displays the highest CVSS score recorded for this library over the past week, along with the associated CVE and vulnerability type.
-
Highest EPSS Score Since Past Week: Shows the highest EPSS score recorded for this library during the past week, including the corresponding CVE and vulnerability type.
-
Details: Provides metadata about the library, including the Library Name, Service, Status, Library type, File Path where the library is located, and Observed hosts.
Select Observed hosts to see host ID and time stamp. This information is updated every 24 hours.
-
Recommended actions: Offers guidance on how to mitigate risks, typically by providing a specific version upgrade to resolve the vulnerabilities found in the library.
-
A list of vulnerabilities associated with this library.