: Public <<TMF_BusinessEntity>> Business Entity
Created: 1/10/2022 12:01:58 PM
Modified: 4/15/2022 10:30:22 AM
Project:
Advanced:
An information security "vulnerability" is a mistake in software that can be directly used by a hacker to gain access to a system or network. <br/><br/>CVE considers a mistake a vulnerability if it allows an attacker to use it to violate a reasonable security policy for that system (this excludes excluding entirely "open" security policies in which all users are trusted, or where there is no consideration of risk to the system). <br/><br/>For CVE, a vulnerability is a state in a computing system (or set of systems) that either: <br/><br/>   · allows an attacker to execute commands as another user <br/>   · allows an attacker to access data that is contrary to the specified access restrictions for that data <br/>   · allows an attacker to pose as another entity <br/>   · allows an attacker to conduct a denial of service <br/><br/>source:  http://cve.mitre.org<br/>
Attribute
Public String
  cceName
Details:
Notes: Unique identifier to system configuration issues in order to facilitate fast and accurate correlation of configuration data across multiple information sources and tools.  The cceName represents a configuration that makes a resource vulnerable.<br/>
Public String
  cveName
Details:
Notes: CVE Identifiers (also called "CVE names," "CVE numbers," "CVE-IDs," and "CVEs") are unique, common identifiers for publicly known information security vulnerabilities. CVE identifiers have "entry" or "candidate" status. Entry status indicates that the CVE Identifier has been accepted to the CVE List while candidate status (also called "candidates," "candidate numbers," or "CANs") indicates that the identifier is under review for inclusion in the list. <br/><br/>source:  http://cve.mitre.org<br/>
Public String
  description
Details:
Notes: A brief description of the vulnerability<br/>
Public DateTime
  disclosureDateTime
Details:
Notes: The date and time the vulnerability was publicly disclosed<br/>
Public DateTime
  discoveredDateTime
Details:
Notes: The date and time the vulnerability was discovered.<br/>
Public DateTime
  exploitPublishedDateTime
Details:
Notes: The date and time the exploit for the vulnerability was published.<br/>
Public DateTime
  lastModifiedDateTime
Details:
Notes: The last date and time the vulnerability was updated<br/>
Public DateTime
  publishedDateTime
Details:
Notes: The date and time the vulnerability was published to the public.<br/>
Public URI
  reference
Details:
Notes: URI to amplifying information about the vulnerability<br/>
Public String
  technicalDescription
Details:
Notes: Details on the technical characteristics of the vulnerability<br/>
Element Source Role Target Role
«TMF_BusinessEntity» SecurityEvent
Business Entity  
Name: _securityVulnerability
 
Name: _securityEvent
 
Details:
 
«TMF_BusinessEntity» SecurityVulnerabilityTool
Business Entity  
Name: _securityVulnerability
 
Name: _securityVulnerabilityToolConfiguration
 
Details:
 
«TMF_BusinessEntity» SecurityVulnerabilityCategoryAssignment
Business Entity  
Name: securityVulnerability
 
Name: securityVulnerabilityCategory
 
Details:
 
«TMF_ABE» Security Vulnerability ABE
ABE «TMF_ABEIsComposedByEntity»
Name:  
 
Name:  
 
Details:
 
«TMF_BusinessEntity» CommonWeaknessEnumeration
Business Entity  
Name: _securityVulnerability
 
Name: _securityVulnerabilityCWEReference
 
Details:
 
«TMF_BusinessEntity» SecurityVulnerabilityFixAction
Business Entity  
Name: _securityVulnerability
 
Name: _securityVulnerabilityFixAction
 
Details:
 
«TMF_BusinessEntity» SecurityVulnerabilitySoftware
Business Entity  
Name: _securityVulnerability
 
Name: _securityVulnerabilitySoftware
 
Details:
 
«TMF_BusinessEntity» EntityIdentification
Business Entity  
Name: _securityVulnerability
 
Name: _entityIdentification
 
Details:
 
Element Source Role Target Role
«TMF_BusinessEntity» SecurityEntity
Business Entity  
Name: _securityEntity
 
Name: _securityVulnerability
 
Details:
 
«TMF_BusinessEntity» SecurityThreatExploit
Business Entity  
Name: _securityThreatExploit
 
Name: _securityVulnerability
 
Details:
 
«TMF_BusinessEntity» SecurityThreatTechnique
Business Entity  
Name: _securityThreatTechnique
 
Name: _securityVulnerability
 
Details:
 
Tag Value
IsCoreEntity False
Details:
Values: true,false
Default: False
rsa_guid _44fUcGpyEd-YIudmhftTlg
Details:
 
Property Value
isActive: 0
isFinalSpecialization: 0