How can I view vulnerabilities identified in source code across multiple assets?

To view the vulnerabilities identified in source code across multiple assets, follow the steps below:

  1. Login into I3 Portal
  2. Using the left floating menu navigate to Analytics —> Vulnerabilities —> Code and click on Code Vulnerabilities button in the top ribbon menu
  3. You can filter code vulnerabilities using the below:
    • Specify search text in the Search box. This is searched in the following: Source filename, Description, Source code snippet and Status
    • Specify the State of the finding i.e. Open / Resolved / Ignored
    • Click on the charts (Rating, OWASP Categories, CWE Distribution, Tags) for further filtering
  4. To view details for a specific code finding, click on the Line number link displayed in the Line # column for that finding.