Skip to main content

Documentation Index

Fetch the complete documentation index at: https://help.dsalta.com/llms.txt

Use this file to discover all available pages before exploring further.

The Vulnerabilities page tracks every security vulnerability identified across your environment — from cloud infrastructure misconfigurations to code dependency CVEs. Each vulnerability includes severity scoring, affected assets, remediation guidance, and SLA tracking.

What vulnerabilities are for

Your auditor needs to see that you identify, prioritize, and fix security vulnerabilities within defined timelines. The Vulnerabilities module centralizes all findings from connected security tools and lets you track remediation progress with full audit history.

How vulnerabilities are collected

Vulnerabilities flow into DSALTA from two sources:
  • Integration-sourced — When you connect vulnerability scanners (Qualys, Wiz), cloud security tools (AWS GuardDuty, GCP Security Command Center, Azure Defender), or code scanners (GitHub Dependabot, Code Scanning, Secret Scanning), findings sync automatically. Each vulnerability shows the integration name as its source.
  • Manual — Upload penetration test results or log vulnerabilities discovered through manual testing.

Viewing your vulnerabilities

Each vulnerability displays:
ColumnDescription
TitleName or description of the vulnerability
IdentifierCVE number or reference ID from the source tool
SeverityCritical, High, Medium, or Low (based on CVSS score)
Base ScoreCVSS base score (0.0–10.0)
StatusOpen, In Progress, Closed, or On Hold
Affected AssetWhich system or component is vulnerable
SourceIntegration name or “Manual”
SLA Due DateDeadline for remediation based on severity
Click any vulnerability to view the full detail page with:
  • Full summary and potential impact description
  • Recommended remediation steps
  • Link to the NVD (National Vulnerability Database) for CVEs
  • List of all affected assets
  • Status change history with timestamps

Working with vulnerabilities

When a new vulnerability appears:
  1. Review the severity and CVSS score to understand the risk.
  2. Identify the affected asset(s) and their classification level.
  3. Assign an owner responsible for remediation.
  4. Update the status as work progresses: Open → In Progress → Closed.
  5. If remediation is not possible immediately, set the status to On Hold with a justification.
Prioritize Critical and High severity vulnerabilities first. Your SLA timelines should reflect the urgency:
  • Critical (CVSS 9.0–10.0) — Remediate within 24–48 hours
  • High (CVSS 7.0–8.9) — Remediate within 7 days
  • Medium (CVSS 4.0–6.9) — Remediate within 30 days
  • Low (CVSS 0.1–3.9) — Remediate within 90 days

Integrations that feed Vulnerabilities

IntegrationWhat syncs
QualysVulnerability scan findings with CVSS scores
WizCloud vulnerability and misconfiguration findings
GitHub DependabotDependency vulnerability alerts
GitHub Code ScanningCode analysis findings (CodeQL)
GitHub Secret ScanningExposed secrets and credentials
AWS GuardDutyThreat findings and security events
GCP Security Command CenterVulnerability and misconfiguration findings
Azure DefenderMicrosoft Defender for Cloud findings
To connect an integration, go to Integrations in the DSALTA sidebar.