View vulnerability libraries
You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.
Before you begin
Role required: App-Sec Manager group
Procedure
Navigate to All > Application Vulnerability Response > * for *Libraries.
The following libraries are available:
| Libraries | Description |
|---|---|
| NVD | List of vulnerabilities found by NVD and includes security checklists, security-related software flaws, misconfigurations, product names, and impact metrics including exploits. |
| CWE | List of community-developed software weakness types. Each CWE record also includes an associated knowledge article that describes the weakness. You cannot escalate a vulnerability from the Common Weakness Enumerations screen, it is for reference only. |
| Third-party | List of imported third-party vulnerabilities in your instance. Contains a list of related references, vulnerable items, exploits, CWEs, and CVEs. |
- Choose a library to view vulnerabilities.
Image omitted: CWE-Entry.png
Example CWE vulnerability entry
Example CWE vulnerability entry
For information on specific fields, see [Application Vulnerability fields](avm-vulnerability-fields.md).