Security Vulnerability Details
Column |
Description |
|||||||||
Source |
The security database system or research organization that has reported the security vulnerability (for example, NVD, Secunia, or another research organization). |
|||||||||
ID |
The ID of the security vulnerability in the format of the advisory organization that reported it:
You can click the hyperlinked URL to open the website for the source advisory to explore more the information about the vulnerability. |
|||||||||
Description |
A description of the security vulnerability pulled from the source. A More/Less link enables you to view the full description and then collapse it as needed. |
|||||||||
Severity |
The severity of the vulnerability (CRITICAL, HIGH, MEDIUM, LOW, or UNAVAILABLE). For more information, see Severity Levels for Security Vulnerabilities. |
|||||||||
CVSS v3.x Score |
The vulnerability’s CVSS (Common Vulnerability Scoring System) score. SBOM Management uses the v3.x scoring system. (The list of vulnerabilities is sorted by this column in descending order.) In some cases, the advisory CVSS v3.x score is unavailable for a vulnerability. SBOM Management reports the unavailable score as a hyphen. If you click the
Note:If a given vulnerability shows a hyphen instead of a score in this column (indicating that no v3.x score is available), the popup still shows the v2.0 score and vector if available. If the neither the v3.x nor the 2.0 score is available for the vulnerability, the popup shows empty values for all fields. The associated Vector value for a v3.x vulnerability has the specific score version—3.0 or 3.1—embedded in the value.
The Vector value is available only if the vulnerability is reported in the NVD. This value (which is hyperlinked) is a compressed textual representation of the values used to derive the score. When you click the link, the NVD Common Vulnerability Scoring System Calculator is opened, showing you the environmental and temporal factors that determine the score. You can use the calculator to tweak these factors as necessary to calculate another score that is more realistic for your software product. (Instructions are provided with the calculator.) This adjusted score can then be used internally to direct your review and remediation processes (but it does not change the reported score). |
|||||||||
Published |
The date on which the vulnerability was originally published, as captured from its source (NVD, Secunia, or another advisory). |
|||||||||
Last Modified |
The date on which the vulnerability was last revised, as captured from its source (NVD, Secunia, or another advisory). If vulnerability has never been revised, the field displays the vulnerability’s published date. |