A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hey there! It sounds like you’re running Defender for Cloud’s agentless container scan on a RHEL UBI–based image (with a Java WAR inside) and you’re seeing CVEs for packages you can’t find in your WAR or in the UBI repo itself. Unfortunately Defender for Cloud’s portal UI doesn’t yet show you the exact file path or layer ID where it discovered each vulnerable package. Here’s how you can still track them down and then remediate:
- Use “View details” on the finding in Defender for Cloud
- In the portal, go to Microsoft Defender for Cloud -> Recommendations -> “Azure registry container images should have vulnerabilities resolved” (or a similar Containers plan recommendation).
- Find your image in the list and click the link on the vulnerability. You’ll get package name, detected version, fixed version and remediation guidance.
- Query the SBOM/installed-software via Cloud Security Explorer
- In the Azure portal, go to Microsoft Defender for Cloud -> Cloud Security Explorer.
- Filter Resource Type to “Containers” -> search for your registry/image.
- Click View details -> Insights -> Has installed software. This pulls in the discovered SBOM and shows every package name + version. You can then match the CVE’s package & version back to where it lives in your image.
- Export raw scan results (JSON)
- If you need more fields (like layer or diff metadata), export the assessment via: • A Defender for Cloud workbook that references the VulnerabilityAssessment findings • The Defender for Cloud REST API (see the “Exporting Azure Container Registry Vulnerability Assessment in Microsoft Defender for Cloud” guide)
- The raw payload sometimes includes additional metadata you can parse.
- Generate your own SBOM / inspect layers locally
- Tools like Syft, Trivy or dive let you inspect every layer and map files/packages to layer digests.
- Run e.g.
syft your-image:tag -o jsonto get a full bill of materials, including the file path inside the image.
Best practices for remediation
- Bake SBOM generation into your CI/CD so you always know exactly which packages (and versions) were added by each Dockerfile layer.
- Keep your UBI base image up-to-date (e.g. pull the latest UBI8 minimal).
- For your WAR, use a dependency‐updater plugin (e.g. Maven versions plugin or Dependabot) to ensure libraries inside the WAR are current.
- After updating your Dockerfile or rebuilding with new base images/deps, repush and wait ~24 hrs for the new scan cycle.
Reference Docs
- Defender for Containers vulnerability assessment: https://docs.microsoft.com/azure/defender-for-cloud/defender-for-containers-vulnerability-assessment-azure
- Troubleshoot container image scanning: https://docs.microsoft.com/azure/defender-for-cloud/agentless-vulnerability-assessment-azure
- Cloud Security Explorer (container software insights): https://docs.microsoft.com/azure/defender-for-cloud/cloud-security-explorer-software-vulnerabilities#create-a-query-to-identify-software-vulnerabilities-in-container-images
- Exporting ACR vulnerability assessment results: https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/exporting-azure-container-registry-vulnerability-assessment-in/ba-p/1255244
If the answer is helpful, kindly upvote it. If you have extra questions about this answer, please click "Comment".