Skip to main content
Vulnerability management

Troubleshooting

Common symptoms and questions in Vulnerability Management, with their causes and what to do.

Find your symptom or question below. Where the answer depends on a capability that is not yet available, the entry says so; the full picture is on Availability.

Access and configuration

Symptom or questionCause and solution
Vulnerabilities is missing from the sidebar.The flag vulnerability_management is off, or you lack vulnerability.finding.read. Ask your tenant administrator.
The page says Vulnerability management is not configured.The flag is off for your tenant. It is switched on under Admin > Regulatory features — see Switch on vulnerability management for your tenant.
I see an access message instead of the findings list.You are missing vulnerability.finding.read. See Roles and permissions.
Record manual finding or Triage finding is not shown.You lack vulnerability.finding.triage, or the finding is no longer in state New.
I cannot switch off cve_detection_ui or dora_detection_workflow.Both become sticky once they have produced regulated records. Switching them off requires a reason and approval by a second person.

Findings

Symptom or questionCause and solution
The page says No vulnerability findings.Nothing has been recorded yet.
"The finding changed. Refresh and retry."Someone else changed the finding at the same time. Reload and check the current state.
I recorded a manual finding and got an existing one back.A finding with the same source asset key and source finding key already exists. This is intended de-duplication.
I cannot set the CI or the CVSS score on a manual finding.Both can be set through the API only on the current release.
Triage did not set a due date.Due-date entry at triage and the remediation policy settings are Planned — not yet available. Triage currently moves the finding from New to Triaged and writes an audit event.
I cannot filter the findings list by state or severity.Filtering and text search exist in the API; the list page does not yet offer filter controls.
I cannot close a finding, mark it false positive or decommissioned.Scan-verified closure and the manual outcomes (manual closure, false positive, decommissioned) are Planned — not yet available.
Can two scanners report the same weakness as one finding?No. Findings are kept per source instance. Cross-source merging requires a separate decision before a second overlapping source is enabled.
Does TENSOR use EPSS or the CISA KEV catalogue?No. Prioritisation uses severity, CVSS, critical-function CIs, service impact, due date and age. Threat-intelligence enrichment is outside the product scope.

CVE exposures on CIs

Symptom or questionCause and solution
TENSOR shows That CVE is already recorded on this CI.The CVE is already recorded on that CI. Open it from the CI's CVEs panel to change its disposition.
I cannot accept the risk of an exposure I recorded.Accepting risk requires a person other than the one who recorded the exposure. Ask a colleague with cmdb.cve.record.
I want to revoke a risk acceptance made on the CVE disposition page.On the CMDB page a risk acceptance is final and cannot be revoked. Time-bounded, revocable risk acceptance in the Vulnerabilities workspace is Planned — not yet available.
What happened to the old CVE tracker?The list /cmdb/cves now redirects to the findings view. The per-CI CVEs panel and the CVE disposition page remain available. See CVEs and lifecycle risk.

Patches and Changes

Symptom or questionCause and solution
Adoption % shows Not assessed.No CI has a status for this patch yet. Record patch status per CI, or let the integration do it.
Deploy patch reports No missing CIs to deploy this patch to.No CI has the status Missing for the patch. Check CI deployment status on the patch.
The Deploy patch confirmation mentions an Emergency change for critical patches.Patch deployments are created as Normal Changes so that they are approved before the work starts. An Emergency Change is only created when it is explicitly requested.
My patch source shows an error.The daily ingestion recorded the last error on the source. Check URL and availability; the next run retries.
I cannot find a settings page to subscribe to patch sources.The subscription settings page is not yet built. Daily ingestion with the Microsoft Update Catalog parser is available.
The known-issue feed shows Last check failed.The feed could not be fetched or read; the error is shown next to it. Only https URLs to public hosts are accepted.
A Standard patch Change I approved is back for a decision.A known issue was reported for a patch it deploys, so it lost its pre-authorization and returned as a Normal Change. Withdrawing the advisory does not re-approve it.
The patch was installed, but the finding is still open.Correct: installation is not proof that the weakness is gone. Scan-verified closure is Planned — not yet available.

Scanners and imports

Symptom or questionCause and solution
My scanner integration reports a sync failure.An enabled scanner that is polled before it is fully wired reports a sync failure instead of a silent "nothing found". Complete the credentials and test the connection.
Can I upload a Nessus file?Not yet. Nessus import with staging, coverage and matching is Planned — not yet available. Keep original scanner files in your scanner.

Evidence

Symptom or questionCause and solution
I cannot find a button for the DORA RTS Art. 10 report.The DORA report is started through the API, not yet from a button. Results appear under Reports > Reports, section History.
Where is the evidence preflight?The evidence preflight and program rollups are Planned — not yet available.