Vulnerabilities
Review vulnerabilities identified in imported SBOMs.
Last updated
Was this helpful?
Review vulnerabilities identified in imported SBOMs.
Use the Vulnerabilities tab to review security issues across imported SBOMs.
Use Search by vulnerability name to find a vulnerability. Select Filter to limit visible results.

The Vulnerabilities tab displays the following information:
Name identifies the vulnerability.
Discovered shows when the vulnerability was discovered.
CVSS shows the vulnerability severity score.
Dependencies lists affected components.
Review status shows the review state.
Exploited (CISA) shows whether CISA lists the vulnerability as exploited.
Select a vulnerability to open its detail view. This view shows:
The vulnerability identifier and discovery date.
The affected dependency and package manager.
Common Weakness Enumeration (CWE) information, when available.
CVSS scores for each supported CVSS version.
CISA Known Exploited Vulnerabilities (KEV) status.
Use Set a review status for SBOM file to select an SBOM or all SBOMs. You can flag the vulnerability as vulnerable or mark it as unaffected.
The Vulnerable dependency section lists dependency versions and their vulnerability status.
Last updated
Was this helpful?
Was this helpful?

