Results

Are detected vulnerabilities monitored?

Updated:2024-06-25 SBOM Central

Are detected vulnerabilities continuously monitored regarding status changes?

The answer is yes!

Example: The notification page shows both added, removed and modified vulnerabilities .

  1. SBOM Central detects a new vulnerability affecting a component that is included in several deliveries.
  2. All deliveries that have monitoring activated generate a notification message and email.
  3. When opening the NVD page, a undergoing reanalysis message is presented.

  1. We decide to wait for the result of the reanalysis before making any evaluations on the vulnerability.
  2. Ticking off the notification.
  3. A new notification message appears. Removed vulnerability messages this time. What does that mean?

  1. A previously detected vulnerability has been rejected, and all affected deliveries monitored in SBOM Central have been updated.