| Security Vulnerability ABE UML Documentation |
Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE
Class SecurityVulnerability
An information security "vulnerability" is a mistake in software that can be directly used by a hacker to gain access to a system or network. CVE considers a mistake a vulnerability if it allows an attacker to use it to violate a reasonable security policy for that system (this excludes excluding entirely "open" security policies in which all users are trusted, or where there is no consideration of risk to the system). For CVE, a vulnerability is a state in a computing system (or set of systems) that either: · allows an attacker to execute commands as another user · allows an attacker to access data that is contrary to the specified access restrictions for that data · allows an attacker to pose as another entity · allows an attacker to conduct a denial of service source: http://cve.mitre.org
Properties:
Alias | |
Classifier Behavior | |
Is Abstract | false |
Is Active | false |
Is Leaf | false |
Keywords | |
Name | SecurityVulnerability |
Name Expression | |
Namespace | Security Vulnerability ABE |
Owned Template Signature | |
Owner | Security Vulnerability ABE |
Owning Template Parameter | |
Package | Security Vulnerability ABE |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability |
Representation | |
Stereotype | |
Template Parameter | |
Visibility | Public |
_entityIdentification
Public EntityIdentification _entityIdentification
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityVulnerabilityRecognizedUsing |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _entityIdentification |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_entityIdentification |
Stereotype | |
Template Parameter | |
Type | EntityIdentification |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityEntity
Public SecurityEntity _securityEntity
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityEntityExhibits |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityEntity |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityEntity |
Stereotype | |
Template Parameter | |
Type | SecurityEntity |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityEvent
Public SecurityEvent _securityEvent
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityEventExposes |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityEvent |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityEvent |
Stereotype | |
Template Parameter | |
Type | SecurityEvent |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityThreatExploit
Public SecurityThreatExploit _securityThreatExploit
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityThreatExploitTargets |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityThreatExploit |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityThreatExploit |
Stereotype | |
Template Parameter | |
Type | SecurityThreatExploit |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityThreatTechnique
Public SecurityThreatTechnique _securityThreatTechnique
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityThreatTechniqueTakesAdvantageOf |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityThreatTechnique |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityThreatTechnique |
Stereotype | |
Template Parameter | |
Type | SecurityThreatTechnique |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityVulnerabilityCWEReference
Public CommonWeaknessEnumeration _securityVulnerabilityCWEReference
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | CommonWeaknessEnumerationRelatedTo |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityVulnerabilityCWEReference |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityVulnerabilityCWEReference |
Stereotype | |
Template Parameter | |
Type | CommonWeaknessEnumeration |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityVulnerabilityFixAction
Public SecurityVulnerabilityFixAction _securityVulnerabilityFixAction
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityVulnerabilityResolvedBy |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityVulnerabilityFixAction |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityVulnerabilityFixAction |
Stereotype | |
Template Parameter | |
Type | SecurityVulnerabilityFixAction |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityVulnerabilitySoftware
Public SecurityVulnerabilitySoftware _securityVulnerabilitySoftware
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SoftwareVulnerableToSecurityVulnerability |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityVulnerabilitySoftware |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityVulnerabilitySoftware |
Stereotype | |
Template Parameter | |
Type | SecurityVulnerabilitySoftware |
Upper | * |
Upper Value | (*) |
Visibility | Public |
_securityVulnerabilityToolConfiguration
Public SecurityVulnerabilityTool _securityVulnerabilityToolConfiguration
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityVulnerabilityScannedUsing |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | _securityVulnerabilityToolConfiguration |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | _securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::_securityVulnerabilityToolConfiguration |
Stereotype | |
Template Parameter | |
Type | SecurityVulnerabilityTool |
Upper | * |
Upper Value | (*) |
Visibility | Public |
cceName
Public String cceName
-
Unique identifier to system configuration issues in order to facilitate fast and accurate correlation of configuration data across multiple information sources and tools. The cceName represents a configuration that makes a resource vulnerable.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | cceName |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::cceName |
Stereotype | |
Template Parameter | |
Type | String |
Upper | * |
Upper Value | (*) |
Visibility | Public |
cveName
Public String cveName
-
CVE Identifiers (also called "CVE names," "CVE numbers," "CVE-IDs," and "CVEs") are unique, common identifiers for publicly known information security vulnerabilities. CVE identifiers have "entry" or "candidate" status. Entry status indicates that the CVE Identifier has been accepted to the CVE List while candidate status (also called "candidates," "candidate numbers," or "CANs") indicates that the identifier is under review for inclusion in the list. source: http://cve.mitre.org
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | cveName |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::cveName |
Stereotype | |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
description
Public String description
-
A brief description of the vulnerability
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | description |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::description |
Stereotype | |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
disclosureDateTime
Public DateTime disclosureDateTime
-
The date and time the vulnerability was publicly disclosed
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | disclosureDateTime |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::disclosureDateTime |
Stereotype | |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
discoveredDateTime
Public DateTime discoveredDateTime
-
The date and time the vulnerability was discovered.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | discoveredDateTime |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::discoveredDateTime |
Stereotype | |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
exploitPublishedDateTime
Public DateTime exploitPublishedDateTime
-
The date and time the exploit for the vulnerability was published.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | exploitPublishedDateTime |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::exploitPublishedDateTime |
Stereotype | |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
lastModifiedDateTime
Public DateTime lastModifiedDateTime
-
The last date and time the vulnerability was updated
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | lastModifiedDateTime |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::lastModifiedDateTime |
Stereotype | |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
publishedDateTime
Public DateTime publishedDateTime
-
The date and time the vulnerability was published to the public.
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | publishedDateTime |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::publishedDateTime |
Stereotype | required |
Template Parameter | |
Type | DateTime |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
reference
Public «baseType» URI reference
-
URI to amplifying information about the vulnerability
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | reference |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::reference |
Stereotype | |
Template Parameter | |
Type | «baseType» URI |
Upper | * |
Upper Value | (*) |
Visibility | Public |
securityVulnerabilityCategory
Public SecurityVulnerabilityCategoryAssignment securityVulnerabilityCategory
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | SecurityVulnerabilityAssigned |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | * |
Name | securityVulnerabilityCategory |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | securityVulnerability |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::securityVulnerabilityCategory |
Stereotype | |
Template Parameter | |
Type | SecurityVulnerabilityCategoryAssignment |
Upper | * |
Upper Value | (*) |
Visibility | Public |
technicalDescription
Public String technicalDescription
-
Details on the technical characteristics of the vulnerability
-
Constraints:
-
Properties:
-
Aggregation | None |
Alias | |
Association | |
Association End | |
Class | SecurityVulnerability |
Datatype | |
Default | |
Default Value | |
Is Composite | false |
Is Derived | false |
Is Derived Union | false |
Is Leaf | false |
Is Ordered | false |
Is Read Only | false |
Is Static | false |
Is Unique | true |
Keywords | |
Lower | 0 |
Lower Value | (0) |
Multiplicity | 0..1 |
Name | technicalDescription |
Name Expression | |
Namespace | SecurityVulnerability |
Opposite | |
Owner | SecurityVulnerability |
Owning Association | |
Owning Template Parameter | |
Qualified Name | SID Models::Enterprise Domain::Enterprise Risk ABE::Enterprise Security ABE::Security Vulnerability ABE::SecurityVulnerability::technicalDescription |
Stereotype | |
Template Parameter | |
Type | String |
Upper | 1 |
Upper Value | (1) |
Visibility | Public |
| Security Vulnerability ABE UML Documentation |