Skip to main content

Vulnerabilities in ServiceOps

Vulnerability management in ServiceOps organizes detected vulnerabilities by patch. Each row in the list is a patch record (PCH-XX) that consolidates all CVEs resolved by that patch. You can see how many CVEs a patch resolves, how many endpoints are missing it, and approve patches in bulk to create a patch deployment, all from a single page.

Prerequisites

Before you access the Vulnerabilities list, ensure:

  • You have the Vulnerability Manager or Vulnerability Specialist Technician role, or your role has View Vulnerability enabled under Admin > Users > Roles
  • A Vulnerability license is active in ServiceOps
  • At least one endpoint is enrolled in Admin > Discovery and Agents > Endpoint Management > Endpoint Scopes
  • The vulnerability database has synced at least once via Admin > Vulnerability Management > Vulnerability Settings
Before You Begin

If the Vulnerabilities list is empty after setup, confirm the patch database has synced. Go to Admin > Patch Management > Patch Administration > Patch Repository and click Update Now to trigger the first sync.

How Does the Vulnerabilities List Work?

ServiceOps compares the OS and software inventory collected from each enrolled endpoint against the local vulnerability database. When installed software matches a known CVE, ServiceOps creates or updates the corresponding patch record. Each patch record (PCH-XX) groups together all CVEs that a single patch resolves, and shows how many endpoints are missing that patch.

The list updates after each scan completes. Scans run automatically when the database updates, when you enroll new endpoints, or when new discovery data arrives. They also run when an endpoint's configuration changes. You can refresh the list manually at any time.

To remediate, select one or more patch records and approve them. Approving a patch creates a patch deployment in the Patch Management module. Each patch record is otherwise read-only; ServiceOps updates it automatically when patch data changes in the central repository or when endpoint scan results change.

Vulnerabilities List Page

The Vulnerabilities List page shows all detected vulnerability patches across your enrolled endpoints. Use the filters and export options to review and prioritize findings and act quickly.

Go to Vulnerability Management > Vulnerabilities.

Vulnerabilities list page showing Detected Vulnerability Patches filter, patch ID, name, severity, exploited CVEs, non exploited CVEs, impacted systems, and category columns

The page has the following controls:

  1. Filter dropdown: Switches between saved filters. Shows Detected Vulnerability Patches by default. The out-of-the-box filters are:
FilterDescription
Detected Vulnerability Patches (default)No condition; shows all vulnerability patches detected to date
Critical Vulnerability PatchesSeverity = Critical
Reboot Required PatchesReboot Required = Yes
Approved PatchesApproval Status = Approved
Unapproved PatchesApproval Status = Unapproved
  1. Search bar: Filters the list by any field. Select a field from the dropdown then type a value.

  2. Export: Sends selected columns to your logged-in Technician email address as CSV or Excel. Also, you can password protect the Excel file.

    Export Vulnerability panel showing format selection, password protection, and column selection with Patch ID, Patch Name, Patch Category, Severity fields

  3. Download: Downloads the full list as CSV or Excel with optional password protection.

    Download panel showing Excel/CSV format selection, password protected toggle, and attachment password field

  4. Refresh: Reloads the list to show the latest scan data.

  5. Column Selection: Adds or removes columns from the list view. Preferences are saved per Technician.

    column selection

  6. More Options: Opens additional actions including Auto Refresh Interval to set how often the list refreshes automatically. You can set the interval of 5, 10, 20, 25, or 30 minutes.

    auto refresh interval

  7. Bulk Operations: Select one or more patch rows and click Take Action to apply one of the following actions:

    • Approve: Changes the status of declined patches to approved.
    • Decline: Changes the status of approved patches to declined, excluding them from deployment workflows.
    • Remediation: Available for approved patches only. Redirects you to the Patch Deployment creation page, where you can configure and publish the deployment.

    Bulk Operations

  8. Grid: The grid displays the Detected Vulnerability Patches by default. Each row is a patch record (PCH-XX) that groups one or more CVEs. The default visible columns are:

FieldDescription
IDUnique patch identifier in PCH-XX format
NameFull patch name including KB number
SeverityRisk level assigned to the patch
Exploited CVEsCVE IDs in this patch that have known active exploitation
Non Exploited CVEsCVE IDs in this patch with no known active exploitation
Impacted EndpointsCount of enrolled endpoints where this patch is missing
CategoryPatch category, for example Updates, Security Updates

Additional fields are available through Column Selection.

Patch Details page

The Patch Detail page shows full patch context: severity, approval status, impacted endpoints, linked CVEs, and installation history.

Click any patch ID in the list to open the Patch Detail page. The following page appears.

Vulnerability detail page showing patch header fields, Decline button, More Options menu, Other Info panel, Patch Details section, and tab navigation

Header fields

The top section shows the patch's key attributes:

FieldDescription
Patch CategoryCategory of the patch, for example Updates or Security Updates
SeveritySeverity level assigned to the patch
Approval StatusCurrent approval state, for example Approved or Pending
Test StatusWhether the patch has been tested, for example Not Tested
Release DateDate the patch was released by the vendor
KB NumberMicrosoft Knowledge Base article number for the patch
Superseded StatusWhether a newer patch supersedes this one
Reference URLVendor support article link for the patch
TagsTags can be added or removed below the header fields.
Patch DetailsThe full patch description from the vendor. Click the expand icon to view it in full.

A. Associated Actions

Each tab gives you a different view, from impacted endpoints and linked CVEs to installation status and audit history.

Shows the endpoints where this patch is Missing, Installed, or Ignored. Use the sub-filter on the left to switch between the three states.

Endpoint tab showing Missing sub-filter selected with a list of endpoint records including ID, hostname, IP address, and OS details

FieldDescription
Endpoint IDUnique endpoint identifier in EP-XX format. Click to open the endpoint's detail page, where you can view the CVEs detected on that device.
Host NameHostname of the enrolled device
IP AddressCurrent IP address of the device
PollerPoller assigned to this endpoint, if applicable
Agent VersionVersion of the Motadata agent installed on the device
OS NameOperating system name, for example Microsoft Windows Server 2019
OS VersionFull OS build version string
Service PackService pack level installed on the device
ArchitectureProcessor architecture, for example 64 BIT
Used ByUser currently associated with the device
Remote OfficeRemote office assignment for the device

B. Associated Actions

Shows the deployment and installation status of this patch per endpoint.

Installation tab showing column headers for endpoint ID, hostname, IP address, configuration type, deployment date, and installation status

FieldDescription
Endpoint IDUnique endpoint identifier in EP-XX format
Host NameHostname of the enrolled device
IP AddressCurrent IP address of the device
Configuration TypeDeployment configuration used for this patch
Deployment DateDate and time the patch was deployed to the endpoint
Installation StatusCurrent state of the patch on the endpoint, for example Installed or Failed
Retry StatusWhether a retry attempt was made after a failed installation
Download StatusWhether the patch file was successfully downloaded to the endpoint
Task TypeType of deployment task, for example Patch Deployment
ActionsAvailable actions for this installation record

More Options

Three actions are available from the top-right of the detail page:

ActionDescription
RefreshReloads the list to show the latest scan data.
DeclineMarks the patch as declined. Declined patches are excluded from deployment.
Download to File ServerAvailable from the More Options menu. Downloads the patch file to the configured file server for offline distribution.

More Options menu expanded showing Download to File Server option next to the Decline button

Read-Only Record

The vulnerability detail page fields are read-only. ServiceOps updates the record automatically when patch data changes in the central repository or when endpoint scan results change.

Other Info

The Other Info panel on the right side shows additional metadata:

Other Info panel showing additional vulnerability metadata fields
FieldDescription
UUIDUnique system identifier for the patch record
ArchitectureTarget architecture, for example 64 BIT
SourceHow the patch was detected, for example Patch Scanning
StatusPublication status, for example Published
Download StatusWhether the patch file has been downloaded to the server
Download OnDate and time the patch was downloaded
Download SizeSize of the patch file
Reboot RequiredWhether a device restart is needed after installation
Support UninstallationWhether the patch can be uninstalled
Approved ByTechnician or system that approved the patch
Approved OnDate and time of approval
Patch TypeType classification, for example OS Patch
Created DateDate the patch record was created in ServiceOps
Last Updated DateDate the record was last modified
Created ByUser or system that created the record
Last Updated ByUser who last modified the record

Example

Your security team receives a vendor alert about a new Critical CVE affecting a widely installed application. You open Vulnerability Management > Vulnerabilities and apply the Critical Vulnerabilities filter. The relevant patch record appears with Exploit Status = Yes and 47 Impacted Systems. You click the patch ID to open the Patch Detail page, review the linked CVEs on the Vulnerabilities tab, and check the Endpoint tab to see which devices are missing the patch. You click an Endpoint ID to open the endpoint detail page and confirm the CVEs detected on that device. Back on the Vulnerabilities list, you select the patch record and click Take Action > Approve. ServiceOps creates a patch deployment in the Patch Management module, and the fix is queued for the 47 affected endpoints.

Troubleshooting

If something isn't working as expected, expand the relevant item below for the cause and fix.

Vulnerabilities list is empty after setup

Cause: The local vulnerability database has not synced yet, or no endpoints are enrolled.

Fix: Go to Admin > Vulnerability Management > Vulnerability Settings and click Update Now. Confirm at least one endpoint is enrolled in Admin > Vulnerability Management > Endpoints Scope.

A known CVE is missing from the list

Cause: The local database is stale, or the affected endpoint is not enrolled in scope.

Fix: Trigger a manual database update from Vulnerability Settings. Confirm the affected endpoint appears in the Endpoints Scope list.

Download produces an empty file

Cause: The active filter returns zero results.

Fix: Clear the active filter or switch to Detected Vulnerabilities before downloading.

CVE IDs are not clickable in the Impacted Endpoints view

Cause: Your role has View Vulnerability but not the permission to navigate to CVE records from that context.

Fix: Ask your administrator to review the role permissions under Admin > Users > Roles.

Detail page shows fewer impacted endpoints than expected

Cause: Some affected endpoints are not enrolled in scope, or an agent is offline and not reporting.

Fix: Check the Vulnerability Endpoints list to confirm enrollment and agent status for the missing devices.