Product Announcementspmonaghan (Veracode, Inc.) asked a question.

🌟 SCA Update: Reminder about changes coming on July 17th

This is a reminder to Software Composition Analysis (SCA) customers that they will see changes to their scan results on July 17th stemming from the following updates:

  1. Of the customers who are still using version 2 of the Common Vulnerability Scoring System (CVSS), approximately 40% will be moved to CVSS v3 as part of Veracode's plan to deprecate support for CVSS v2. Contact your Customer Success Manager (CSM) to find out whether your account is part of this batch. If you want to move sooner, contact support@veracode.com and ask them to activate CVSS v3. For answers to frequently asked questions, please see https://info.veracode.com/rs/790-ZKW-291/images/2023-06-FAQs-for-CVSSv2-Customers.pdf.
  2. SRCCLR-SID-35451 will be changed from Medium to High severity for both CVSS v2 and CVSS v3. This change will have an impact on .NET customers who have this vulnerability in their portfolio.
  3. CVE-2022-41915 will be changed from Low to High severity for CVSS v2 only. The CVSS v3 severity will NOT change.
  4. The 32 CVEs listed below will be changed from Medium to Very High severity for CVSS v2 only. Again, the CVSS v3 scores will NOT change. Customers are encouraged to avoid these changes by contacting support@veracode.com and asking them to activate CVSS v3.
  • CVE-2014-125087, CVE-2020-36618, CVE-2020-36641, CVE-2021-23451, CVE-2021-46848, CVE-2022-25147, CVE-2022-2564, CVE-2022-25759, CVE-2022-26969, CVE-2022-32221, CVE-2022-32224, CVE-2022-3515, CVE-2022-35255, CVE-2022-36085, CVE-2022-36364, CVE-2022-36594, CVE-2022-37022, CVE-2022-37434, CVE-2022-37614, CVE-2022-39227, CVE-2022-39237, CVE-2022-39353, CVE-2022-40315, CVE-2022-41900, CVE-2022-41915, CVE-2022-43402, CVE-2022-43403, CVE-2022-43404, CVE-2022-44900, CVE-2022-46170, CVE-2023-23914, CVE-2023-25344, CVE-2023-28154

Thank you.

 

 


Topics (8)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.