
Product Announcements — pmonaghan (Veracode, Inc.) asked a question.
On July 17, 2023, Veracode will be adjusting CVSS v2 severity scores for the 34 CVEs listed in the attached spreadsheet. The v3 scores will remain the same except for one. The CVSS v3 score for SRCCLR-SID-35451 will be changed from 5.3 (Medium) to 7.5 (High). After these adjustments are made, you may see a change in your SCA results if your projects or applications contain any of these vulnerabilities.
As a reminder, National Vulnerability Database retired CVSS v2 in July 2022, so we encourage all customers to contact support about moving your account from CVSS v2 to v3. We will start the process of moving batches of customers in July 2023. Please contact your Customer Success Manager to find out your move date. Thank you.
P.s. For search purposes, I am listing here the CVEs whose v2 scores will be changing: CVE-2022-41915, SRCCLR-SID-35451, CVE-2014-125087, CVE-2022-39353, CVE-2023-28154, CVE-2022-2564, CVE-2022-32224, CVE-2022-37614, CVE-2023-25344, CVE-2022-36364, CVE-2022-36085, CVE-2022-37022, CVE-2022-37434, CVE-2022-41900, CVE-2023-23914, CVE-2021-46848, CVE-2022-40315, CVE-2022-32221, CVE-2022-3515, CVE-2022-25147, CVE-2021-23451, CVE-2022-36594, CVE-2022-39237, CVE-2022-43403, CVE-2022-43404, CVE-2020-36618, CVE-2022-26969, CVE-2022-43402, CVE-2022-25759, CVE-2022-39227, CVE-2022-35255, CVE-2022-44900, CVE-2020-36641, CVE-2022-46170.
.png)
According to my knowledge CVSS (Common Vulnerability Scoring System) is a framework used to assess the severity of security vulnerabilities. The scores are calculated based on various metrics such as exploitability, impact, and complexity. In the information you provided, Veracode will be adjusting the CVSS v2 severity scores for the 34 CVEs listed in the attached spreadsheet. It's unclear what the adjustments will be for each individual vulnerability, but the document should specify the changes.