• Anthony Fielding (Veracode)

    Hi @AGorr125347 (Community Member)​,

    If you click on the blue help icon next to the policy name, it will show you the policy rules that were evaluated. It could be that this application has not been subjected to a static analysis in the previous quarter or there has been no Manual Penetration Test (MPT) in the previous year and so the application is failing the scan requirements.

     

    Thanks,

    Anthony Fielding

    Expand Post
    • AGorr125347 (Community Member)

      Thank you Anthony for all your assistance and education. If you are tracking a support incident, the case may be closed.

       

      Arthur Gorr

  • AGorr125347 (Community Member)

    Thank you Anthony, this is helpful.

    Reviewing the Policy Control tab for the application I see we are passing the MPT (with expiration) but we no not pass because of violated rules that have mitigated flaws. Is that correct? All the other requirements are passing.

     

    So: if a rule was mitigated then is it ever possible to have the policy pass? Can you recommend how to pass the VL5 requirement?

     

    Thank you

    Arthur Gorr

     

    2020-04-27 09_51_02-Veracode Platform

     

    Expand Post
    • Anthony Fielding (Veracode)

      Hi @AGorr125347 (Community Member)​,

      Thanks for expanding on your question. I have taken a look at the application using the link you sent me and can confirm that it is not passing the requirement for VL5 purely because there was no Manual Penetration Test (MPT). The Help Centre has an article on the Veracode Levels here: https://help.veracode.com/reader/Xsx4w5mUPDcfuttA34wSpw/gJ1C_8~OEP8ZNaMYv7TilA. Whilst the UI does appear to suggest there is an issue relating to a mitigated flaw, it was in fact due to a missing manual test. To attain VL5 you should look to request a Manual Penetration Test from within the platform. I hope that answers your question.

       

      Kind regards,

      Anthony

      Expand Post
  • AThigpen129883 (Community Member)

    I had a similar situation, and it turns out that I had a vulnerable dependency discovered through SCA. I would also recommended checking results there for the scan, as they do not show under the results of the overall scan results page.

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.