VSA-9 Software Management: Patch Visibility

Description

Resolution for users experiencing patch visibility issues in Software Management. Suggested helpdesk user Level 1. Estimated time to resolution 20–30 minutes.

Issue Synopsis

The Vulnerabilities page will only display items that are currently missing or the history of items that were missing but are now applied.

Note If a patch is suppressed it will be removed from the list of vulnerabilities, however, if a patch is rejected for deployment it will remain listed as a vulnerability.

Resolution Summary

The issue occurs because the Suppressed and Rejected tabs only display manual actions, not policy-based actions. Suppression removes a patch from the Vulnerabilities list and reporting, while rejection prevents automatic deployment but allows the patch to continue displaying as a vulnerability.

Behavior differs slightly between Software Management 1.0 and 2.0.

  • Software Management 1.0
    Rejected patches may still show in the Vulnerabilities page. When an agent is scanned, it reports the rejected patch as missing. Although the patch appears under Vulnerabilities, the policy rejection ensures it will not install. Recommend using suppression for vulnerabilities you do not want to deploy. Suppression removes them from the Vulnerabilities page and ensures they are excluded from dashboards and reporting metrics.Screenshot.png

  • Software Management 2.0
    The Vulnerabilities page shows both currently missing patches and the history of patches that were missing but are now applied. Suppressed patches are removed entirely from the Vulnerabilities list. Rejected patches remain visible as vulnerabilities but are not deployed.

To confirm patch status, administrators should:

  • Use the Vulnerabilities page to identify missing patches.

  • Use the Suppressed tab to view manually suppressed patches.

  • Use the Rejected tab to view manually rejected patches.


Step-by-Step Resolution

  1. Open Software Management.

  2. Select Vulnerabilities to view all missing patches.

    • In 1.0, rejected patches appear here but will not deploy.

    • In 2.0, rejected patches also appear here, while suppressed patches are hidden.

  3. To check suppressed patches:

    • Go to the Suppressed tab.

    • Review patches manually marked as suppressed.

    • Suppressed patches will not appear in Vulnerabilities or reporting.

  4. To check rejected patches:

    • Go to the Rejected tab.

    • Review patches manually marked as rejected.

    • Rejected patches will still appear in Vulnerabilities but will not deploy.

  5. Confirm whether the action was applied manually or by policy.

    • Manual actions appear in Suppressed/Rejected tabs.

    • Policy actions must be verified with logs.


Callouts, Tips, and Warnings

Warning: No Canceling Scheduled Patch Installs
Once a deployment is scheduled from the Vulnerabilities page the instruction is sent to the agent and cannot be canceled.


Applicable Helpdesk Tickets

  • 5468027 Missing Patches Not Showing in Tabs

Have more questions?

Contact us

Was this article helpful?
3 out of 12 found this helpful

Provide feedback for the Documentation team!

Browse this section