Note:
This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.
If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the KB2556844 and documentation before proceeding.
If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
Exception Management enables organizations to efficiently handle and document vulnerability exceptions. It provides a controlled process for requesting, reviewing, and approving exceptions to vulnerable findings, ensuring transparency and compliance. By automating workflows and capturing exception justifications, it helps reduce operational bottlenecks while maintaining risk visibility and audit readiness.
- Manual and Automated Exception Request and Approval Workflow - Streamline the process of submitting, reviewing, and approving exception requests with customizable workflows that ensure accountability and speed up decision making.
- Comprehensive Exception Tracking and Audit Trails - Maintain full visibility into all exceptions with detailed records of approvals, justifications, and timelines to support compliance and audit readiness.
Fixed:
- Missing approver levels after migrating to Unified Security Exposure Management (USEM).
- A security issue that might allow unauthorized access to exception settings.
- Cursor jumping in the script editor within USEM Workspace.
- Resolved packaging and translation issues in Exception Management for Security Exposure Management.
- Issues with change approval email notifications after migrating to USEM, including duplicate subject lines, an incorrect recipient greeting, and the requester's name displaying as an internal ID.
- Approvers receive email notifications if an exception request was unassigned.
- Editable Change Approval fields from the list view are now read-only as intended.
- After a policy exception is cancelled the source record's state is reverted.
- Expiring an exception or false-positive request doesn't create a duplicate remediation task.
- Fixed several hardcoded text strings in Exception Management so they can be properly translated.
- A performance issue where checking approver access to exception requests loads an excessive number of records, causing slowdowns.
- The Defer Until field's inconsistent behavior between the Security Exposure Management workspace and the native UI.
- The GRC exception flow when a policy exception is cancelled or closed.
- A security issue related to query handling in risk reduction eligibility checks.
- The deferral count on vulnerable items no longer intermittently fails to update.
- A security issue that might allow unauthorized access to record counts through a data broker.
- A security issue with user-controlled field names in a data broker.
- The Update button is no longer disabled when the requested date is within the allowed maximum duration.
- A vulnerable item opens as expected if the state-change approval flow fails.
- A security issue with read-only access that permitted modifications to exception change approval records.
- A security issue where request approvals are processed without verifying record assignment.
- Risk Reduction requests no longer get stuck in 'Draft' state when the questionnaire feature is enabled.
- Required-field validation errors are now properly identified for screen readers, and the Request Exception dialog now has an accessible title.
- Exception rules now correctly handle failure scenarios for new findings that don't yet have a remediation task configured.
Changed:
- Enhancements to the request exception dialog so it includes a title, improving accessibility and compliance.
- Enhancements to error handling for blank required fields in Security Exposure Management. The system identifies errors when required fields are left blank in Security Exposure Management, ensuring users are notified of missing information.
- Enhancements for exception rule handling for new findings without remediation tasks. The system processes new findings that lack remediation tasks when exception rules fail.
- No additional system requirements. This update is fully compatible with existing Exception Management and Compensating Controls configurations