Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Vulnerability Artifacts

A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.

The weakness or defect is in the requirements, designs, or implementations of the code found in a software or hardware component. This weakness is directly exploited to negatively impact the confidentiality, integrity, or availability of that system.

CVE is a list of information security vulnerabilities and exposures that provides common names for publicly known problems [CVE].

For example, if a piece of malware exploits CVE-2015-12345, a Malware object could be linked to a Vulnerability object that references CVE-2015-12345.

  • Define Vulnerability
    A vulnerability is a weakness or flaw in a software or hardware component that can be exploited by attackers to compromise confidentiality, integrity, or availability.
  • Create a CWE record
    Create a Common Weakness Enumeration (CWE) record to represent a weakness identified in a system or product, and link it to relevant vulnerabilities.
  • Create a Product
    Create New Product feature allows you to record the product’s version, vendor, and classification details, to ensure products are accurately linked to vulnerabilities and related records.
  • Create a Vendor to a Vulnerability
    Use this feature to create a vendor. Once created, you can associate the vendor to a product or link them to a vendor comment.
  • Create Remediations
    Create a remediation record to document a fix or workaround for a vulnerability affecting a specific product.
  • Access the Vulnerability Entities
    The TISC uses the following entities to store and organize vulnerability, product, and vendor intelligence data.
  • Fetch Vulnerability Data
    Fetch vulnerability related data such as configuration items, vulnerable entries, and business context.

Parent Topic:TISC Library Repository

Related topics

Observables

Indicators

Threat Entities

Other Objects

View RSS Feeds

Working with Reports in TISC

MITRE-ATT&CK Repository

Relationships Objects

Potential Relationships

Vulnerability relationship mapping