Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Modify the severity for a CVE or TPE

As a vulnerability manager or analyst, you can modify the severity level of Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.

Before you begin

Role required:

  • sn_vul.vulnerability_analyst, or sn_vul.vulnerability_admin for host vulnerable items (VITs)
  • sn_vul.app_sec_manager, sn_vul.app_developer for application vulnerable items (AVITs)
  • sn_vul_container.vulnerability_analyst or sn_vul_container.vulnerability_admin for container vulnerable items (CVITs)

Procedure

  1. Navigate to Workspaces > Vulnerability Manager Workspace > Lists > Libraries.

  2. Open the appropriate entry:

    • CVEs (NVD): To modify the severity of a CVE.
    • TPEs: To modify the severity of a TPE.
    • Select Modify severity from the More Actions icon
Image omitted: ellipsis-icon-workspace.png
ellipsis\_icon
  1. Select the new severity level from the drop-down.

  2. Provide a justification for your update.

  3. Select Submit.

    Note:

    • You can revert to the original source severity using the Reset Severity option from the More Actions menu. This option appears only after you modify the severity.
    • The Modified severity field appears only when you change the source severity. If you reset it to the original value, the field is removed.
    • The system will use the Modified severity for risk calculations starting from the next scheduled job onwards. If the severity is reset, the original source severity will be applied instead.

Parent Topic:Use the List view in the Vulnerability Manager Workspace