SVigo172076 (Community Member) asked a question.

New User Query: Mitigation Approval and Flaw Policy

Hi everyone!

I'm a new Veracode user, I would like to discuss a situation I encountered. I proposed and gained approval for a mitigation solution to address a reported flaw. Veracode's module was utilized for this purpose (which is not detected automatically), with it I've mitigated 300 flaws with the same ID.

However, despite the successful mitigation, I have noticed that the flaw score remains unchanged an the mitigated flaws are shown with a green icon and a tooltip that says "Fix required by policy". Flaw no longer impact result"

What is the step that I 'm missing? Is Mitigation the same as fix or not? If not, the mitigation that I proposed, shoud be the fix, because there is no other way to manage the issue at the code.

 

I would appreciate guidance on any additional steps required to ensure compliance with Veracode's policy.

 

Thank you for your assistance and support.

Regards,

SV


  • Hi @SVigo172076 (Community Member)​ ,

     

    It seems that you have successfully mitigated the flaws and were approved by your internal AppSec team. So consider them that they are closed.

    Regarding the score; it is a complex algorithm behind scoring mechanics. The score depends on the severity of flaws getting closed than the number of flaws that are getting closed. With the limited information provided above, it is not possible to give the exact reason.

    I would recommend you schedule a consultation call to discuss this.

    You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.

    Regards,

    Kashif

     

     

    Expand Post

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.