All Products
Search
Document Center

Security Center:DescribeVulList

Last Updated:Aug 28, 2026

Queries vulnerabilities by type.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeVulList

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Lang

string

No

The language of the content in the request and response. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

Ids

string

No

The IDs of vulnerabilities. You can specify up to 50 IDs. Separate multiple IDs with commas (,).

282,281,283

Remark

string

No

The asset remark, which can be the private IP address, public IP address, or asset name.

1.2.XX.XX

GroupId

string

No

The ID of the asset group.

Note

You can call the DescribeAllGroups operation to query the IDs of asset groups.

9207613

Type

string

Yes

The type of the vulnerability. Valid values:

  • cve: Linux software vulnerability

  • sys: Windows system vulnerability

  • cms: Web-CMS vulnerability.

  • app: application vulnerability detected by web scanner

  • emg: urgent vulnerability.

  • sca: application vulnerability detected by software component analysis

cve

Uuids

string

No

The UUIDs of the servers on which you want to query the vulnerabilities. Separate multiple UUIDs with commas (,).

Note

You can call the DescribeCloudCenterInstances operation to obtain the UUIDs.

1587bedb-fdb4-48c4-9330-****

Name

string

No

The alias of the vulnerability.

oval:com.redhat.rhsa:def:20172836

AliasName

string

No

The name of the vulnerability.

RHSA-2019:0230-Important: polkit security update

StatusList

string

No

The status of the vulnerability. Separate multiple statuses with commas (,). Valid values:

  • 1: unfixed

  • 2: fix failed

  • 3: rollback failed

  • 4: being fixed

  • 5: being rolled back

  • 6: being verified

  • 7: fixed

  • 8: fixed and to be restarted

  • 9: rolled back

  • 10: ignored

  • 11: rolled back and to be restarted

  • 12: not found

  • 20: expired

1,2,3

Necessity

string

No

The priority to fix the vulnerability. Separate multiple priorities with commas (,). Valid values:

  • asap: high

  • later: medium

  • nntf: low

asap,later,nntf

Dealed

string

No

Specifies whether the vulnerabilities are fixed. Valid values:

  • y: yes

  • n: no

n

CurrentPage

integer

No

The number of the page to return. Default value: 1.

1

PageSize

integer

No

The number of entries per page. Default value: 10.

20

AttachTypes

string

No

The additional vulnerability type. Required when Type is set to app. Set the value to sca.

Note

If set to sca, both application vulnerabilities and software component analysis vulnerabilities are returned. Otherwise, only application vulnerabilities are returned.

sca

TargetType

string

No

The type of the asset on which the vulnerability is detected. Valid values:

  • k8s: Kubernetes component.

  • uuid: server.

  • containerId: container.

k8s

ClusterId

string

No

The cluster ID.

c88fb10da1168494091db6aafc5dd****

VpcInstanceIds

string

No

The VPC ID. Separate multiple IDs with commas (,).

ins-133****,ins-5414****

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID of the member in the resource directory.

Note

You can call the DescribeMonitorAccounts operation to obtain the IDs.

1232428423234****

UseNextToken

boolean

No

Whether to use token-based pagination. If true, TotalCount is not returned. Valid values:

  • true

  • false

false

NextToken

string

No

The pagination token from the previous response. Not required for the first request.

E17B501887A2D3AA5E8360A6EFA3B***

RaspDefend

integer

No

Whether application protection is supported. Valid values:

  • 0: no.

  • 1: yes.

0

Response elements

Element

Type

Description

Example

object

CurrentPage

integer

The page number of the returned page.

1

RequestId

string

The request ID.

2F26AB2A-1075-488F-8472-40E5DB486ACC

PageSize

integer

The number of entries per page.

20

TotalCount

integer

The total number of vulnerabilities returned.

2

VulRecords

array<object>

The information about the vulnerability.

array<object>

Status

integer

The status of the vulnerability. Valid values:

  • 1: unfixed.

  • 2: fix failed.

  • 3: rollback failed.

  • 4: being fixed.

  • 5: being rolled back.

  • 6: being verified.

  • 7: fixed.

  • 8: fixed and to be restarted.

  • 9: rolled back.

  • 10: ignored.

  • 11: rolled back and to be restarted.

  • 12: not found.

  • 20: expired.

1

RaspDefend

integer

Whether application protection is supported. Valid values:

  • 0: no.

  • 1: yes.

Note

If this parameter is not returned, the application protection feature is not supported.

1

RaspStatus

integer

The application protection mode. Valid values:

  • 0: unprotected.

  • 1: Monitor mode.

  • 2: Block mode.

  • 3: disabled.

1

Type

string

The type of the vulnerability. Valid values:

  • cve: Linux software vulnerability.

  • sys: Windows system vulnerability.

  • cms: Web-CMS vulnerability.

  • emg: urgent vulnerability.

  • app: application vulnerability.

  • sca: application vulnerability that is detected by using software component analysis.

cve

ModifyTs

integer

The timestamp when the vulnerability status was modified. Unit: milliseconds.

1620404763000

InternetIp

string

The public IP address of the asset.

1.2.XX.XX

PrimaryId

integer

The ID of the vulnerability.

101162078

Tag

string

The tag that is added to the vulnerability.

oval

K8sClusterId

string

The ID of the cluster.

Note

Returned only for Security Center Ultimate edition with container asset protection.

c863dc93bed3843de9934d4346dc4****

K8sNodeId

string

The ID of the node.

Note

Returned only for Security Center Ultimate edition with container asset protection.

i-bp1ifm6suw9mnbsr****

InstanceName

string

The name of the asset.

testInstance

Online

boolean

Whether the Security Center agent is online. Valid values:

  • true

  • false

true

OsVersion

string

The OS name of the asset.

linux

Name

string

The name of the vulnerability.

oval:com.redhat.rhsa:def:20170574

Progress

integer

The fix progress.

100

ResultCode

string

The fix result code.

0

InstanceId

string

The ID of the asset.

i-bp18t***

Related

string

The related CVE IDs, separated by commas (,).

CVE-2017-7518,CVE-2017-12188

IntranetIp

string

The private IP address of the asset.

1.2.XX.XX

LastTs

integer

The timestamp when the vulnerability was last detected. Unit: milliseconds.

1620404763000

FirstTs

integer

The timestamp when the vulnerability was first detected. Unit: milliseconds.

1554189334000

RegionId

string

The region ID of the asset.

cn-hangzhou

Necessity

string

The priority to fix the vulnerability. Valid values:

  • asap: high.

  • later: medium.

  • nntf: low.

Note

Fix high-risk vulnerabilities as soon as possible.

asap

RepairTs

integer

The fix timestamp in milliseconds. Returned only for vulnerabilities fixed in the Security Center console.

1541207563000

Uuid

string

The UUID of the asset.

04c56617-23fc-43a5-ab9b-****

K8sPodName

string

The name of the pod.

Note

Returned only for Security Center Ultimate edition with container asset protection.

deployment-riskai-7b67d68975-m****

ContainerId

string

The container ID.

04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****

GroupId

integer

The ID of the asset group.

281801

ResultMessage

string

The message that indicates the vulnerability fixing result.

timeout

K8sNamespace

string

The namespace.

Note

With Ultimate edition, the value is from container assets. Otherwise, it is from the Security Center agent.

default

AliasName

string

The name of the vulnerability.

RHSA-2019:0230-Important: polkit security update

K8sNodeName

string

The name of the node.

Note

Returned only for Security Center Ultimate edition with container asset protection.

deployment-riskai-7b67d68975-m****

ExtendContentJson

object

The extended information about the vulnerability.

Status

string

The status of the vulnerability. Valid values:

  • 1: unfixed.

  • 2: fix failed.

  • 3: rollback failed.

  • 4: being fixed.

  • 5: being rolled back.

  • 6: being verified.

  • 7: fixed.

  • 8: fixed and to be restarted.

  • 9: rolled back.

  • 10: ignored.

  • 11: rolled back and to be restarted.

  • 12: not found.

  • 20: expired.

1

EmgProof

string

The returned message that indicates the urgent vulnerability.

com.xxl.rpc.util.XxlRpcException: xxl-rpc request data is empty.\n\tat com.xxl.rpc.remoting.net.impl.servlet.serve"

Ip

string

The public IP address of the asset that is associated with the vulnerability.

1.2.XX.XX

PrimaryId

integer

The ID of the vulnerability.

111

Os

string

The name of the operating system.

centos

Tag

string

The tag that is added to the vulnerability.

oval

LastTs

integer

The timestamp when the vulnerability was last detected. Unit: milliseconds.

1620404763000

Description

string

The description of the vulnerability.

kernel version:5.10.84-10.2.al8.x86_64

OsRelease

string

The information about the operating system version.

7

AliasName

string

The name of the vulnerability.

RHSA-2019:0230-Important: polkit security update

Target

string

The URL of the vulnerability.

http://39.99.XX.XX:30005/toLogin

AbsolutePath

string

The path to the package of the software that has the vulnerability.

/roo/www/web

RpmEntityList

array<object>

The information about RPM Package Manager (RPM) packages.

object

FullVersion

string

The complete version number.

3.10.0-693.2.2.el7

Version

string

The version number of the package of the software that has the vulnerability.

3.10.0

MatchDetail

string

The reason why the vulnerability is detected.

python-perf version less than 0:3.10.0-693.21.1.el7

ImageName

string

The name of the image.

registry_387ytb_xxx

Path

string

The path to the software that has the vulnerability.

/usr/lib64/python2.7/site-packages

ContainerName

string

The name of the container.

k8s_67895c4_xxx

Name

string

The name of the RPM package.

python-perf

UpdateCmd

string

The command that is used to fix the vulnerability.

*** update python-perf

MatchList

array

The rules that are used to detect the vulnerability.

string

The rule that is used to detect the vulnerability.

fastjson(jar) extendField.safemode equals false

Pid

string

The process ID.

8664

ExtendField

string

The extended information about the software package that has the vulnerability.

{"msg_no_lookups_configured_CVE_2021_44228": "false", "jndi_class_not_exist": "false"}

cveList

array

The CVE list.

string

The CVE.

CVE-2016-8610

Necessity

object

Indicates whether the vulnerability needs to be fixed.

Status

string

The status of the vulnerability priority score. Valid values:

  • none: No score is generated.

  • pending: The score is pending calculation.

  • normal: The calculation is normal.

normal

Time_factor

string

The time score.

1.0

Enviroment_factor

string

The environment score.

1.0

Is_calc

string

Indicates whether the vulnerability priority score is calculated. Valid values:

  • 0: no.

  • 1: yes.

1

Total_score

string

The vulnerability priority score.

Score ranges and recommended actions:

  • If the score is from 13.5 to 15, the vulnerability is high-risk. Fix immediately.

  • If the score is greater than or equal to 7 but less than 13.5, the vulnerability is medium-risk. Fix at your convenience.

  • If the score is less than 7, the vulnerability is low-risk. You can ignore it.

7.8

Cvss_factor

string

The Common Vulnerability Scoring System (CVSS) score.

7.8

Assets_factor

string

The asset importance score. Valid values:

  • 2: important asset.

  • 1: common asset.

  • 0: test asset.

1

Bind

boolean

Whether Security Center is authorized to scan the asset. Valid values:

  • true

  • false

true

OsName

string

The OS name of the asset.

CentOS 7.2 64-bit

AuthVersion

string

The authorized Security Center edition. Valid values:

  • 1: Basic.

  • 6: Anti-virus.

  • 5: Advanced.

  • 3: Enterprise.

  • 7: Ultimate.

  • 10: Value-added Plan.

3

RealRisk

boolean

Whether the vulnerability is easily exploited. Valid values:

  • true

  • false

true

RuleTag

string

The tag of this vulnerability. Valid values:

  • AI: AI-related components.

AI

Image

string

The name of the image.

registry-cn-**-vpc.ack.**.com/acs/ack-node-problem-detector:v0.8.16-8ed7053-**

Namespace

string

The namespace.

kube-system

NextToken

string

The pagination token for the next request.

E17B501887A2D3AA5E8360A6EFA3B***

Examples

Success response

JSON format

{
  "CurrentPage": 1,
  "RequestId": "2F26AB2A-1075-488F-8472-40E5DB486ACC",
  "PageSize": 20,
  "TotalCount": 2,
  "VulRecords": [
    {
      "Status": 1,
      "RaspDefend": 1,
      "RaspStatus": 1,
      "Type": "cve",
      "ModifyTs": 1620404763000,
      "InternetIp": "1.2.XX.XX",
      "PrimaryId": 101162078,
      "Tag": "oval",
      "K8sClusterId": "c863dc93bed3843de9934d4346dc4****",
      "K8sNodeId": "i-bp1ifm6suw9mnbsr****",
      "InstanceName": "testInstance",
      "Online": true,
      "OsVersion": "linux",
      "Name": "oval:com.redhat.rhsa:def:20170574",
      "Progress": 100,
      "ResultCode": "0",
      "InstanceId": "i-bp18t***",
      "Related": "CVE-2017-7518,CVE-2017-12188",
      "IntranetIp": "1.2.XX.XX",
      "LastTs": 1620404763000,
      "FirstTs": 1554189334000,
      "RegionId": "cn-hangzhou",
      "Necessity": "asap",
      "RepairTs": 1541207563000,
      "Uuid": "04c56617-23fc-43a5-ab9b-****",
      "K8sPodName": "deployment-riskai-7b67d68975-m****",
      "ContainerId": "04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****\n",
      "GroupId": 281801,
      "ResultMessage": "timeout",
      "K8sNamespace": "default",
      "AliasName": "RHSA-2019:0230-Important: polkit security update",
      "K8sNodeName": "deployment-riskai-7b67d68975-m****",
      "ExtendContentJson": {
        "Status": "1",
        "EmgProof": "com.xxl.rpc.util.XxlRpcException: xxl-rpc request data is empty.\\n\\tat com.xxl.rpc.remoting.net.impl.servlet.serve\"",
        "Ip": "1.2.XX.XX",
        "PrimaryId": 111,
        "Os": "centos",
        "Tag": "oval",
        "LastTs": 1620404763000,
        "Description": "kernel version:5.10.84-10.2.al8.x86_64",
        "OsRelease": "7",
        "AliasName": "RHSA-2019:0230-Important: polkit security update",
        "Target": "http://39.99.XX.XX:30005/toLogin",
        "AbsolutePath": "/roo/www/web",
        "RpmEntityList": [
          {
            "FullVersion": "3.10.0-693.2.2.el7",
            "Version": "3.10.0",
            "MatchDetail": "python-perf version less than 0:3.10.0-693.21.1.el7",
            "ImageName": "registry_387ytb_xxx",
            "Path": "/usr/lib64/python2.7/site-packages",
            "ContainerName": "k8s_67895c4_xxx",
            "Name": "python-perf",
            "UpdateCmd": "*** update python-perf",
            "MatchList": [
              "fastjson(jar) extendField.safemode equals false"
            ],
            "Pid": "8664",
            "ExtendField": "{\"msg_no_lookups_configured_CVE_2021_44228\": \"false\", \"jndi_class_not_exist\": \"false\"}"
          }
        ],
        "cveList": [
          "CVE-2016-8610"
        ],
        "Necessity": {
          "Status": "normal",
          "Time_factor": "1.0",
          "Enviroment_factor": "1.0",
          "Is_calc": "1",
          "Total_score": "7.8",
          "Cvss_factor": "7.8",
          "Assets_factor": "1"
        }
      },
      "Bind": true,
      "OsName": "CentOS  7.2 64-bit",
      "AuthVersion": "3",
      "RealRisk": true,
      "RuleTag": "AI",
      "Image": "registry-cn-**-vpc.ack.**.com/acs/ack-node-problem-detector:v0.8.16-8ed7053-**",
      "Namespace": "kube-system"
    }
  ],
  "NextToken": "E17B501887A2D3AA5E8360A6EFA3B***"
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 InnerError InnerError
400 IllegalParam Illegal param
400 DataNotExists %s data not exist
400 RdCheckNoPermission Resource directory account verification has no permission.
400 MissingType Type is mandatory for this action. Type is mandatory for this action.
500 RdCheckInnerError Resource directory account service internal error.
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.