For the complete documentation index, see llms.txt. This page is also available as Markdown.

Vulnerabilities

Review vulnerabilities identified in imported SBOMs.

Use the Vulnerabilities tab to review security issues across imported SBOMs.

Use Search by vulnerability name to find a vulnerability. Select Filter to limit visible results.

The Vulnerabilities tab displays the following information:

  • Name identifies the vulnerability.

  • Discovered shows when the vulnerability was discovered.

  • CVSS shows the vulnerability severity score.

  • Dependencies lists affected components.

  • Review status shows the review state.

  • Exploited (CISA) shows whether CISA lists the vulnerability as exploited.

See information about a specific vulnerability

Select a vulnerability to open its detail view. This view shows:

  • The vulnerability identifier and discovery date.

  • The affected dependency and package manager.

  • Common Weakness Enumeration (CWE) information, when available.

  • CVSS scores for each supported CVSS version.

  • CISA Known Exploited Vulnerabilities (KEV) status.

Use Set a review status for SBOM file to select an SBOM or all SBOMs. You can flag the vulnerability as vulnerable or mark it as unaffected.

The Vulnerable dependency section lists dependency versions and their vulnerability status.

Last updated

Was this helpful?