Release v1.3.20 - IBM/ServiceNow-Guardium-Vulnerability-Assessment GitHub Wiki

Issues addressed in this release

New features:

  • GRD-73361, issue 29 Scan on demand
    • Rate limit of one scan per minute (configurable)
    • Ability to disable automatic import of test results via IBM Guardium > Settings (preferences)
  • issue 47 Parallel processing of managed collectors
  • issue 60 Reapply CI Lookup Rule from Guardium Data Source view
  • issue 59 Simplification of CI Lookup Rule where Correlation ID == Guardium.Datasource.Name
  • GUARD-I-1519 Group scan errors into Remediation Task and Test Result Group
  • GRD-73181, issue-61 Disable aggregator by default
  • issue-50 Reduce OAuth requests
  • Documentation updates (this wiki now has all documentation)
  • Third-party test ID will now show: Guardium-X20123 where X is the Central Manager ID if there are more than 1 central managers and custom query test ID is greater than or equal to 20000.
  • Third-party test ID will now show: Guardium-00123-2 if a test severity has been tuned to be Major. (1=Critical, 2=Major, 3=Minor, 4=Caution, 5=Informational)

Bug fixes:

  • GRD-72606 Ignore empty object in online_report response
  • issue 57 Attach test result detail when it is too big for Vulnerability > Detection > Proof field
  • GRD-73490 Toggle credential encryption in ECC Queue -- default is to encrypt credentials in the ECC Queue log and MID server will decrypt before passing to Guardium
  • Export data sources to Guardium when database export rule is run
  • Delete data source entries in ServiceNow if Guardium data source is deleted
  • GRD-74663 Ignore disabled aggregators and collectors
  • GRD-74694 Second central manager is only partially synchronized
  • SGA-11 Vulnerable Item must show test severity set when "tuning" the assessment test

Bug fixes not seen in any published release:

  • GRD-74707 Rescan error
  • GRD-74747 Use ServiceNow library to reapply CI lookup rule
  • GRD-74768 Reapply CI lookup rule shows "No matching rule found"
  • GRD-75395 New data source is not imported if one is deleted with the same name
  • GRD-71651 Duplicate data source on export