Generating vulnerability service reports

Red Hat Lightspeed 1-latest

Communicate the exposure of RHEL systems to CVE security vulnerabilities

Red Hat Customer Content Services

Abstract

Generate vulnerability service reports to communicate the exposure of RHEL systems to CVE security vulnerabilities.

Chapter 1. Overview of Red Hat Lightspeed vulnerability service reporting

The ability to convey the security exposure of your infrastructure to different stakeholders, such as the DevOps team, security team, and executive team, is vital.

You can use the vulnerability service to download the following reports to analyze offline or share with others:

Executive reports
PDF summary and overview of the security vulnerability exposure of your infrastructure, intended for executive audiences
CVE reports
PDF report of selected, filtered CVEs to which your infrastructure is exposed, intended to highlight and share vulnerability data
Vulnerability data export
Export of selected CVE data, based on filters you have in place when you perform the export, to a JSON or CSV file

Chapter 2. Executive reports

You can download a high-level executive report summarizing the security exposure of your infrastructure. Executive reports are two- to three-page PDF files, designed for an executive audience.

Executive reports include the following information:

On page 1
  • Number of RHEL systems analyzed
  • Number of individual CVEs to which your systems are currently exposed
  • Number of security rules in your infrastructure
  • List of CVEs that have advisories
On page 2
  • Percentage of CVEs by severity (CVSS base score) range
  • Number of CVEs published by 7, 30, and 90-day time frames
  • Top three CVEs in your infrastructure, including security rules and known exploits
On page 3
  • Security rule breakdown by severity
  • Top three security rules, including severity and number of exposed systems

2.1. Download an executive report

You can download an executive report for key stakeholders in your security organization:

Procedure

  1. Navigate to the This content is not included.Security > Vulnerability > Reports tab and log in if necessary.
  2. On the Executive report card, click Download PDF.
  3. Click Save File and click OK.

Verification

  1. Verify that the PDF file is in your Downloads folder or other specified location.

2.2. Download an executive report using the vulnerability service API

You can download an executive report by using the vulnerability service API.

Procedure

Chapter 3. Reports by CVEs

You can create PDF reports showing a filtered list of CVEs your systems are exposed to. Give each report a relevant name, apply filters, and add user notes to present focused data to specific stakeholders.

You can apply the following filters when setting up the PDF report:

  • Security rules. Show only CVEs with the security rules label.
  • Known exploit. Show only CVEs with the Known exploit label.
  • Severity. Select one or more values: Critical, Important, Moderate, Low, or Unknown.
  • CVSS base score. Select one or more ranges: All, 0.0-3.9, 4.0-7.9, 8.0-10.0, N/A (not applicable).
  • Business risk. Select one or more values: High, Medium, Low, Not defined.
  • Status. Select one or more values: Not reviewed, In review, On-hold, Scheduled for patch, Resolved, No action - risk accepted, Resolved via mitigation.
  • Publish date. Select from All, Last 7 days, Last 30 days, Last 90 days, Last year, or More than 1 year ago.
  • Applies to OS. Select the RHEL minor version(s) of systems to filter and view.
  • Tags. Select groups of tagged systems.
  • Advisory. Select whether to display only CVEs that have associated advisories (errata), only CVEs without advisories, or all CVEs.

The CVE report lists the CVEs and links each to its corresponding CVE page in the Red Hat CVE database. The list is ordered primarily by the CVE’s publication date, with the most recently published CVEs at the top.

3.1. Create a PDF report of CVEs

You can create a point-in-time snapshot of CVEs that potentially affect your systems.

Prerequisites

  • You must be logged in to Red Hat Hybrid Cloud Console.

Procedure

  1. Navigate to the This content is not included.Security > Vulnerability > Reports page in the Red Hat Lightspeed application.
  2. On the Report by CVEs card, click Create report.
  3. Make selections as needed in the pop-up card.

    1. Optional: Customize the report title.
    2. In the Filter CVEs by section, click each drop-down list and select a value.
    3. Select Tags to only include systems in a tagged group of systems.
    4. Under CVE data to include, Choose columns is activated by default, allowing you to clear columns you do not want to include. Leave all boxes checked, or click All columns to show everything.
    5. Optional: To provide context for the intended report audience, you can add notes.
  4. Click Export report. It can take at least one minute for the report to be generated.
  5. Select to open or save the PDF file, if you such request, and click OK.

3.2. Additional resources

Chapter 4. Reports by RHEL versions

The Vulnerability Exposure by OS report feature shows the number of CVEs reported against up to five selected minor versions of RHEL. The report also includes a graph showing the number and severity of the CVEs for each selected RHEL version.

Note

The report does not indicate actual CVEs on the systems registered to Red Hat Lightspeed in your environment. The comparison for each minor version is based on a generic system with the base package list and with all errata for that minor version installed.

You can use the report to estimate the extent of vulnerability exposure for your systems within specific RHEL versions, and then use the information to make informed upgrade decisions.

Note

The Vulnerability Exposure by OS report feature supports RHEL major and minor versions from RHEL 6.9 to RHEL 10.1 and later.

4.1. Create a PDF report by RHEL versions

You can create a report, filter results by RHEL versions, and save it in PDF format on your local machine.

Prerequisites

  • You have Vulnerability viewer access to your environment in Red Hat Lightspeed.

Procedure

  1. From the Red Hat Lightspeed dashboard, navigate to SecurityVulnerabilityReports.
  2. Select Report by operating system versions.
  3. Click Create Report. The Vulnerability exposure by operating system dialog box appears.
  4. Select up to five versions of RHEL to compare in the report.
  5. Click Export PDF for a PDF report, or click Export CSV for a CSV-formatted file. The exported file downloads to your system automatically.

Chapter 5. Export vulnerability data as JSON, CSV, or PDF files

Use the vulnerability service to export data for CVEs on systems in your RHEL infrastructure. After applying filters in the vulnerability service to view a specific set of CVEs or systems, you can export data based on those criteria.

You can access these reports through the Red Hat Lightspeed service, export and download as CSV, JSON, or PDF files.

5.1. Export CVE data from the vulnerability service

You can export and save selected data from the vulnerability service in JSON, CSV, and PDF formats.

Prerequisites

  • You must be logged in to Red Hat Hybrid Cloud Console.

Procedure

  1. Navigate to the This content is not included.Security > Vulnerability > CVEs page.
  2. Apply filters and use the sorting functionality at the top of each column to locate specific CVEs.
  3. Above the list of CVEs and to the right of the Filters menu, click the Export icon, Export , and select Export to JSON, Export to CSV, or Export as PDF based on your download preferences.
  4. Select a download location and click Save.

Chapter 6. Enable notifications and integrations

You can enable the notifications service in the Red Hat Hybrid Cloud Console to send notifications whenever a vulnerability event gets triggered. Using the notifications service frees you from having to continually check the Red Hat Lightspeed dashboard for event-triggered notifications.

For example, you can configure the notifications service to:

  • send an email message whenever a security issue affects systems in your installation
  • send an email digest of all the vulnerability events that take place each day

In addition to sending email messages, you can configure the notifications service to send event data in other ways:

  • Using an authenticated client to query Red Hat Lightspeed APIs for event data
  • Using webhooks to send events to third-party applications that accept inbound requests
  • Integrating notifications with applications such as Splunk to route event notifications to the application dashboard

Here are some of the ways administrators and users interact with the notifications service:

  • A user with at least the Notifications administrator or RHEL administrator role permissions sets up behavior groups for events in the notifications service. Behavior groups specify the delivery method for each notification and whether the notifications are sent to all users or just to Organization Administrators.
  • An Organization Administrator creates a User Access group with at least the Notifications viewer or Notifications administrator role, and then adds account members to the group.
  • Users who receive email notifications from events might set their user preferences to receive individual emails for each event, or a daily digest of events.

Chapter 7. Reference materials

Learn more about the vulnerability service, or other Red Hat Lightspeed services and capabilities to maintain a better security for you systems.

Legal Notice

Copyright © Red Hat.
Except as otherwise noted below, the text of and illustrations in this documentation are licensed by Red Hat under the Creative Commons Attribution–Share Alike 3.0 Unported license . If you distribute this document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, the Red Hat logo, JBoss, Hibernate, and RHCE are trademarks or registered trademarks of Red Hat, LLC. or its subsidiaries in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
XFS is a trademark or registered trademark of Hewlett Packard Enterprise Development LP or its subsidiaries in the United States and other countries.
The OpenStack® Word Mark and OpenStack logo are trademarks or registered trademarks of the Linux Foundation, used under license.
All other trademarks are the property of their respective owners.