Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Manual ingestion of vulnerabilities for Application Vulnerability Response

Security professionals and application testers can create and manage the application penetration test findings within the Penetration Testing Workspace.

The Penetration testing forms are available in the Penetration Testing Workspace to document the vulnerabilities identified in the core business applications.

The security professionals and application testers can manually import findings from external sources and platforms using the provided templates in Excel or CSV format. All the vulnerability findings are made available in the Penetration Testing Workspace.

To access and download the template for uploading to Penetration testing workspace, navigate to All > Manual AVIT Ingestion > Upload File UI.

A new penetration test form is created for every file upload for the respective application. All the vulnerability findings within that upload are associated to the same penetration test form. The Application Name must match with the records in of the tables:

  • Application Table
  • Business Application Table
  • Scanned Application Table

The Application Name is a mandatory field present in the template for identifying the vulnerabilities present within an application, associated to a penetration test form. Any record missing the Application Name will not be processed and skipped during vulnerability creation.

Note: Mandatory fields in the template are necessary for processing the penetration test findings. It is necessary to ensure all the fields in the template are intact to prevent any issues during the processing of penetration test findings.

Column NameMandatoryDescriptionAvailable Options/ Max characters in strings
Risk ratingMandatorySeverity of the application vulnerable itemCritical High Medium Low None \(Default\)
Requested byMandatoryRequested by151
CWE categoryMandatory\(Fill only one column\)CWE ID255
Vulnerability IDMandatory\(Fill only one column\)Vulnerability ID255
ApplicationMandatoryApplication Name255
Purpose of applicationMandatoryPurpose of application4000
Types of sensitive dataMandatoryList types of sensitive data accessible from applications40
List of compliance programsMandatoryList of compliance programs4000
Technology stack detailsMandatoryTechnology stack details4000
Application teamMandatoryApplication team Name; group responsible for developing and maintaining software applications100
URLs to testMandatoryURLs to test4000
Steps to reproduceMandatorySteps to reproduce1000
Technical detailsMandatoryTechnical details1000
Assigned toMandatoryAssigned to \(individual responsible for conducting penetration tests and generating security findings\)151
Assignment groupMandatoryAssignment group \(group responsible for conducting penetration tests and generating security findings\)151