BigFix Insights for Vulnerability Remediation 4.3 is Available Now!

Release Summary

Features and Enhancements of the new IVR v. 4.3

  • Native Qualys Integration on IVR v. 4 Architecture
  • NiFi-Powered Data Orchestration
  • Superseded Vulnerability Filtering
  • Qualys File-Based Import Support
  • Bug Fixing

Summary

We are happy to announce the release of BigFix Insights for Vulnerability Remediation (IVR) 4.3.0. This release brings full Qualys support to the IVR v. 4 architecture, offering significant performance gains and granular control over data ingestion.

  • High-Performance Architecture with Apache NiFi:
    The Qualys integration now leverages Apache NiFi to optimize the data ingestion pipeline. This ensures faster, more reliable processing of vulnerability data, significantly improving performance when importing large datasets and reducing the overall synchronization window.
  • Configurable Superseded Vulnerabilities:
    IVR v. 4.3 provides customers with greater control over their data footprint. A new setting within the IVR console allows users to toggle whether superseded Qualys vulnerabilities should be imported. This allows teams to focus exclusively on active, actionable risks or maintain a historical record based on their specific compliance needs.
  • Unified IVR v. 4 Benefits:
    Qualys users can now take full advantage of the modern IVR framework, including:
    • Pre-correlated Content: Leverage pre-mapped vulnerability-to-fixlet data for faster remediation.
    • Device and Vulnerability Views: Switch between asset-centric and vulnerability-centric dashboards in the WebUI for better visibility.
    • Streamlined Remediation: Initiate patching directly from the Device Details or Vulnerability pages.
  • Flexible File Import Options:
    In addition to the native connector, IVR v. 4.3 supports the import of vulnerabilities via files exported from Qualys. This provides a critical fallback and flexibility for air-gapped environments or specific reporting workflows, all while maintaining the correlation accuracy of the v. 4 engine.

The goal of IVR remains the same: to help align Security and Operations teams with intelligent patching prioritization and automated remediation, reduce the time between vulnerability discovery and remediation, and greatly reduce risk by reducing the vulnerable attack surface.

Important Notice for IVR v. 2 Users:

Customers currently using IVR v. 2 with the Qualys connector should plan their migration to IVR 4.3 immediately. IVR v. 2 utilizes legacy Qualys APIs that will reach end-of-support starting in June. Transitioning to IVR 4.3 ensures continued service and leverages the modern, supported API framework for more robust data integration.

Resources

Site Versions

Site Type Name Version
Fixlet Site BigFix Insights for Vulnerability Remediation 203
WebUI Site WebUI IVR 22
2 Likes

@ADL, are 4.3’s features only for Qualsys integration? Are there any impacts or changes relevant to Tenable integrations?

Hi Lauren, no fix or enhancement on the Tenable Integration is included in this release.

Thanks @ADL for the confirmation.

-Andrew

Does the correlation identify superseded patch content? This is a typical Qualys issue - Qualys identifies vulnerabilities and recommends the first available patch content. Can BigFix suggest the latest patch content and take care of supersedence?

Hi Ravi,

Yes, BigFix handles patch supersedence automatically.
IVR ingests the Qualys data, maps it to the correct BigFix Fixlet, and automatically checks if that patch is superseded. If it is, BigFix bypasses the stale update and directs you to the latest patch available.

This ensures you fix the vulnerability with a single, up-to-date deployment rather than chasing a chain of outdated patches.

2 Likes

Thanks ADL for this update

Would it be possible to install this without any Qualsys/Tenable integration but only rely for time being on CSV Imports? In our environment we’re leveraging CrowdStrike and I can get manual export going from CrowdStrike and use that as source.

How can I perform clean install, we did do initial testing with version 2 which at the time had Tenable integration configured, when I install/update to Version 4.3 I still see the “Tenable” option available.

Any ETA when CrowdStrike integration would also be made available?