All integrations

ManageEngine Vulnerability Manager Plus Integration with DefectDojo

ManageEngine Vulnerability Manager Plus Integration with DefectDojo

ManageEngine Vulnerability Manager Plus (VMP) is an endpoint vulnerability management product from ManageEngine, a division of Zoho Corporation. It assesses managed hosts against vulnerability advisories and ties each vulnerability to the patch that resolves it. DefectDojo reads VMP vulnerability data as a JSON export, and DefectDojo Pro can also pull it directly through an API connector.

ManageEngine Vulnerability Manager Plus Integration with DefectDojo

Our desktop and server teams live in ManageEngine Vulnerability Manager Plus, and the application security team lives in DefectDojo. Importing VMP data into DefectDojo put endpoint CVEs next to everything else we track, with the host as the component, so the same vulnerability on two machines stays two findings with two owners. Because VMP already knows the patch for each vulnerability, the finding arrives with the fix attached.

Why ManageEngine Vulnerability Manager Plus Matters

Endpoints are where unpatched software tends to pile up, and VMP is built around finding and closing that gap.

  • It reports vulnerabilities per managed host, so exposure is tied to a specific machine.
  • Each vulnerability can carry the patch description and patch ID that fix it.
  • It records CVSS v3 and, for older advisories, CVSS v2 scores alongside CVE identifiers.
  • It tracks a status per vulnerability, so closed items can be told apart from open ones.

Advantages of This Integration

What the integration adds on top of the VMP console:

  • Severity that means what it says. VMP grades on Microsoft's MSRC scale. DefectDojo maps Important to High and Moderate to Medium instead of letting them fall to Info, so SLAs apply at the right tier.
  • Closed is closed, unknown stays open. Rows with a status of Close, Closed, Fixed, or Remediated import as inactive. Any other status, including one DefectDojo has not seen before, stays active so a live vulnerability is not hidden.
  • One finding per host. The host is the component, so a patch rollout shows exactly which machines are done and which are not.
  • CVE-level filtering. Every CVE in VMP's single cveids string is extracted into vulnerability IDs, sorted, so you can search DefectDojo by CVE across endpoints and application scans.
  • File and connector agree. The parser mirrors the DefectDojo Pro connector and uses the same scan type, so file imports and API syncs deduplicate.
  • Shared workflow. SLAs, assignment, risk acceptance for hosts that cannot be patched yet, Jira tickets, and metrics all apply.

How This Integration Works

DefectDojo supports VMP with the ManageEngine Vulnerability Manager Plus Scan scan type, by file (UI Import, API Import, Universal Importer in DefectDojo Pro) or through the DefectDojo Pro API connector.

1. Get a VMP export. The parser expects the JSON shape VMP returns for its vulnerability list: an object with a vulnerabilities array alongside VMP's paging metadata. An object naming the list data or results, or a bare array, also works. Each row is already fused, carrying both the vulnerability and the host it was found on, so nothing has to be joined. This file path is intended for environments that cannot grant VMP API credentials.

2. Import the file. In the UI, open an Engagement, choose Import Scan Results, select ManageEngine Vulnerability Manager Plus Scan, and upload the JSON. Using the API, in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=ManageEngine Vulnerability Manager Plus Scan" 
  -F "file=@vmp-export.json" 
  -F "product_name=corporate-endpoints" 
  -F "engagement_name=Endpoint Vulnerabilities" 
  -F "auto_create_context=true"

With Universal Importer in DefectDojo Pro:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "ManageEngine Vulnerability Manager Plus Scan" 
  --report-path "./vmp-export.json" 
  --product-name "corporate-endpoints" 
  --engagement-name "Endpoint Vulnerabilities" 
  --auto-create-context

3. Or use the connector (DefectDojo Pro). Generate an API token in VMP under Admin, API key generation. In the DefectDojo Pro UI, add the Vulnerability Manager Plus connector, enter the VMP server URL in Location and the token in Auth Token, and optionally set a Minimum Severity. Each host becomes a Record carrying the vulnerabilities detected on it, and the connector syncs on a schedule.

Data Granularity: What Gets Imported

DefectDojo Field Source in VMP Export Notes
Title vulnerabilityname Falls back to the CVE IDs, then the vulnerability ID
Severity severity Critical; Important and High become High; Moderate and Medium become Medium; Low; Unrated or absent becomes Info
Description Vulnerability, CVEs, host, IP, status Raw cveids text is shown as VMP wrote it
Mitigation patch_description, patchid The patch and its ID
CVSS v3 Score cvss_3_score Falls back to cvss_2_score when v3 is zero or absent
Vulnerability IDs cveids CVE, GHSA, GO, and RHSA identifiers extracted and sorted
Component Name Host resource_name, then fqdn_name, then ip_address
References reference_links Advisory links
Date updatedtime Epoch milliseconds; zero leaves the default date
Active vulnerability_status Inactive for Close, Closed, Fixed, Remediated
Unique ID from Tool Resource and vulnerability IDs vmanplus-<resource id>-<vulnerability id>
Vuln ID from Tool vulnerabilityid Integral numbers render without a decimal
Finding type Static Inventory compared against advisories
Deduplication Unique ID or hashcode Unique ID from tool, falling back to title, severity, component_name

Use Cases

Patch Tuesday follow-through: After a monthly rollout, a reimport closes findings on hosts that took the patch. What remains open is the list of machines that missed the deployment, each with the patch ID in its mitigation.

Unified vulnerability reporting: A security leader reports on Critical and High exposure across applications, containers, and endpoints from one place. VMP findings use the same severity tiers and SLAs, so the numbers are comparable.

Restricted networks: Where DefectDojo cannot reach the VMP server, an administrator exports the vulnerability list and uploads it. When the connector becomes possible, findings deduplicate rather than doubling.

Exceptions with an end date: A legacy server that cannot take a patch until a vendor upgrade gets a risk acceptance with an expiration date, so it returns for review instead of being forgotten.

Operational Tips

  • Model hosts sensibly. One Asset per business unit or environment keeps ownership clear, since the host itself is already the component on each finding.
  • Watch the status column. Statuses such as Mitigated are not in the closed list and import as active; resolve them in VMP or close them in DefectDojo deliberately.
  • Use minimum_severity on import, or the connector's Minimum Severity, if Low and Info rows would bury the team.
  • Reimport into the same Test on a schedule that matches your patch cycle so closures land promptly.
  • Search by CVE ID when a high-profile advisory drops. Extracted vulnerability IDs make it quick to find every endpoint affected.
  • If you use both the file route and the connector, keep them pointed at the same Asset so their findings deduplicate.