Loading
Skip Feed
  1. Show/Hide vulnerable items on Top 10 dashboard

    is it possible to hide items that appear on top 10 dashboard lists?  mgmt wants to know if these lists are configurable to hide items which we choose to ignore if we have external processes to address the vulnerability.

    Question with a best answer.

    Best Answer

    Hello, 

    You cant simply hide specific products aka items from the dashboard but you can create your own products dashboard based on smart groups. 

    For example: 

    You just want to include Firefox, Notepad++, Adobe Flash player in your dashboard. You can simply go to Results > Product smart group and configuration > create a new smart group > and add all three products in your smart groups ( Follow the screenshot below). 

    smart.PNG

     

     

    You can then add your smart group to your dashboard ( Dashboard > Most prevalent insecure software installations > Select your smart group from drop down. 

     

    smart 2.PNG

     

    We hope this will resolve your issue. 

    Regards,

    Raheel 

    Expand Post
    raslam by raslam (Flexera Software)

    RoBo likes this.
    • raslam (Flexera Software)

      Hello, 

      You cant simply hide specific products aka items from the dashboard but you can create your own products dashboard based on smart groups. 

      For example: 

      You just want to include Firefox, Notepad++, Adobe Flash player in your dashboard. You can simply go to Results > Product smart group and configuration > create a new smart group > and add all three products in your smart groups ( Follow the screenshot below). 

      smart.PNG

       

       

      You can then add your smart group to your dashboard ( Dashboard > Most prevalent insecure software installations > Select your smart group from drop down. 

       

      smart 2.PNG

       

      We hope this will resolve your issue. 

      Regards,

      Raheel 

      Expand Post
      Selected as Best

  2. Csia.exe appears to get stuck

    csiscan.log gets stuck on line Windows update scanner searching for updates.   Eventually this times out but why is this happening?  Is this an indicator that the underlying WMI repository is faulty and needs rebuilding?  

    Question with a best answer.

    Best Answer

    Hi, 

    You can quickly check and verify the WMI check if it is working or not. 

    For example : 

    Login to your SVM console > Configuation > Settings 

    Disable check for Microsoft Security Updates

    wua.PNG

    Run the scan and create a log and see if just the WMI check is running fine? If it is then you might need to check your WUA agent status from services , if the WUA service is running or not? for more details, you can check the windows update log. 

    Regards,

    Raheel 

    Expand Post
    raslam by raslam (Flexera Software)

    RoBo likes this.
    • raslam (Flexera Software)

      Hi, 

      You can quickly check and verify the WMI check if it is working or not. 

      For example : 

      Login to your SVM console > Configuation > Settings 

      Disable check for Microsoft Security Updates

      wua.PNG

      Run the scan and create a log and see if just the WMI check is running fine? If it is then you might need to check your WUA agent status from services , if the WUA service is running or not? for more details, you can check the windows update log. 

      Regards,

      Raheel 

      Expand Post
      Selected as Best

  3. Flexera SVM On Prem: How to Integrate with BMC Remedy CMDB - Is there an API for this?

    Our org has Flexera SVM on prem.  We'd like to feed our newly developing BMC Remedy CMDB some data such as endpoint name, system score, and possibly much more.  I have HeidiSQL (per Flexera eng recommendation) and am connected to the database, just to get a sense of the schema, in preparation for the inevitable data modelling.  

    1)  Is there an existing API that can integrate the Flexera db with BMC Helix?  Would anything that is compatible with MariaDB work?

    2) Doe you provide any documentation for the db schema that would assist me isolate the data that is relevant to us?

    3) Is there anything I can do proactively to prepare myself as the Flexera/SCCM/AMS data custodian for a smooth integration with Flexera SVM such as tools, documentation or known limitations?

    Thank you,

    Enterprise Desktop Admin

     

    Expand Post
    Question with a best answer.

    Best Answer

    There is an API for getting data from SVM which is often used for such a purpose. You'll find it documented here: https://docs.flexera.com/csi/api/Default.htm

    We offer this as opposed to a DB Schema (which we do not publish in lieu of the API offering). 

    0_Bob K by 0_Bob K (Flexera Software)

    RoBo likes this.
    • 0_Bob K (Flexera Software)

      There is an API for getting data from SVM which is often used for such a purpose. You'll find it documented here: https://docs.flexera.com/csi/api/Default.htm

      We offer this as opposed to a DB Schema (which we do not publish in lieu of the API offering). 

      Selected as Best

  4. Request for API Details to Retrieve EOL Information from Flexera

    Hello Flexera Support Team,

    We are looking to integrate Flexera data with our reporting and would like to retrieve End-of-Life (EOL) information for operating systems and software products through Flexera APIs.

     

    Could you please help us with the following details?

    1. Which API endpoint(s) can be used to retrieve EOL information for software and operating systems?
    2. Does the API provide the following attributes?
      • EOL Date
      • EOL Status (Supported/Unsupported/EOL)
      • End of Support Date
      • Product Name
      • Product Version
      • Publisher/Vendor
    1. Could you share the relevant API documentation and sample request/response payloads?

     

     

    Expand Post

  5. Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:
    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go crypto/tls version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    Subject: Request updated FNMS Docker Monitor binary built with Go 1.25.7+ (CVE‑2025‑68121)

    Hello Team,

    Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:

    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go

    crypto/tls

    version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    According to the Go project, the vulnerability is fixed only in:

    • Go 1.24.13
    • Go 1.25.7
    • Go 1.26.0‑rc.3

    Can you please provide the latest FNMS Container Monitor / Inventory Agent installer or updated

    fnms-docker-monitor.exe

    built with Go 1.25.7 or later, so we can apply the remediation?

    Expand Post

  6. Update for Adobe Acrobat DC, version 25.001.20693 (Continuous) failing on all PC's with error Returning 1642

    We have downloaded the latest application for adobe acrobat DC (Not reader), and it is failing on all machines with exit code 1642 and error 0x80070643. Please let me know if there is any known issue or what is the solution for this?

    @fawad_laiq​ 


    1 of 2
    • Maheshar_Ali (Flexera Software)

      Hi @deepaknr6​ ,

       

      Thank you for posting this. The issue has been resolved and conveyed to you through the support case.

       

      I hope this helped.

       

      Thanks.

      Expand Post

  7. TIMNPAWC likes this.
    • james_ellis (Flexera)

      Hello,

       

      I see that there is a support case open on this subject. The Engineer will work with you on this through your case. We will update this topic once concluded.

       

      Kind regards,

       

      James

      Expand Post

End of Feed
8 Chatter Feed Items
ALL CONVERSATIONS
UNSOLVED
Unanswered Questions
Skip Feed
  1. Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:
    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go crypto/tls version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    Subject: Request updated FNMS Docker Monitor binary built with Go 1.25.7+ (CVE‑2025‑68121)

    Hello Team,

    Our security scanner (Prisma Compute) detected that the FNMS Docker Monitor component:

    C:\Program Files (x86)\ManageSoft\Container\fnms-docker-monitor.exe

    is built with Go

    crypto/tls

    version 1.25.3, which is vulnerable to CVE‑2025‑68121.

    According to the Go project, the vulnerability is fixed only in:

    • Go 1.24.13
    • Go 1.25.7
    • Go 1.26.0‑rc.3

    Can you please provide the latest FNMS Container Monitor / Inventory Agent installer or updated

    fnms-docker-monitor.exe

    built with Go 1.25.7 or later, so we can apply the remediation?

    Expand Post

  2. Hello,
    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM.

    Hello,

    I have installed WhatsApp for Windows for Windows on my laptop from the Microsoft Store. However, I do not see this as an installed product in SVM. Could it be that SVM see it as a generic Microsoft Redistributed Package. Is there something specific I can search for to find it?

    Any advice much appreciated.

    Howard


  3. SVM Assesment base and integration limit

    Hello Team

    I have some concern about the following point and I need an argent replay please:

    -Does SVM detect configuration vulnerabilities based on CIS benchmarks?!

    -Does SVM integrate with other asset management tools and CMDB?!

    -Does SVM can generate system logs to SIEM solution?!

    Please Advise.

    Thanks, Regards

    Expand Post

  4. Firefox ESR 115.3 64-bit SPS Package

    We created via SVM Patch Publisher using the Flexera Package System, a Firefox 115.3 ESR update to publish to our WSUS.  We configured the package to only install ESR and use the default applicability path for detection (no modification to versioning).  When deployed to our clients, some had their Firefox Current Release version replaced by the ESR version.  We didn't want that to happen, so we recreated the package and changed the version checks for applicability to minimum version 102.0.0.0 and secure version to 115.3.0.0.  After publishing it and deploying, clients running current release were still getting the ESR update.  I checked .sdp files in the folder SVMPatch Cache and it seems the versioning we specified for applicability is getting ignored.  Can we not use this package to only upgrade ESR clients?  Are changes to minimum and secure version supported via SVM Patch Publisher?


  5. Elevate Security and Connectivity: Exploring VPNs on Routers Forum

    Here, we delve into the transformative realm of integrating VPN on router , enhancing both your online security and connectivity. Join discussions that uncover the synergy between Software Vulnerability Management and router-based VPNs. Explore how the combination of robust VPN setups and proactive vulnerability management can fortify your network against potential threats. Engage with experts and enthusiasts to understand how this dynamic duo can elevate your digital experience, safeguarding your data while maintaining seamless connectivity. Discover the potential at the intersection of VPNs on routers and software vulnerability management for a safer, more secure online journey.


  6. 0_Bob K (Flexera Software) asked a question.

    SVM and Log4j

    Your attention is called to this blog post for how SVR and SVM can help you deal with Log4j .

    SVM focuses exclusively on assessing known vulnerable software versions. It uses file signatures to determine the presence of known vulnerable software versions and matches that with research and patches to help you identify and remediate such. So, if Log4j is installed on a system, we will detect it, but that is not typically how Log4j is distributed—rather it is included as a component of another third-party application. In such a case, it will be identified as vulnerable if/when the software including it is disclosed as vulnerable, we write an advisory, and create a file signature to detect it.

    That said, we are prioritizing a potential product enhancement that would allow SVM to provide an awareness report to identify specific components like Log4j embedded within your installed software. This would be a new use case for SVM as it would help provide awareness, but you would not be able to remediate it by patching as SVM is traditionally leveraged. This is due to the fact that the product bundling the component is what needs to be patched, so this would be a new reporting-focused use case versus a patch-focused one. Actually patching a vulnerable component will continue to require targeting the application that is shipping the component, versus the component itself.

    Expand Post

End of Feed
8 Chatter Feed Items
Loading
Software Vulnerability Manager | Flexera Community