Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Vulnerability Impact

Go from a CVE to the applications and releases that ship the affected component. Sort by CVSS and EPSS, and record VEX decisions on the finding so they do not come back on the next scan.

Impact analysis: from a vulnerable package to the applications and releases that ship it.

A CVE names a package and nothing else

A scanner reports a CVE in a package. It does not say which of your applications ship that package, in which releases, or whether someone already decided it does not apply.

Finding affected applications takes a search
Tracing a package to the releases that ship it means going through build output by hand.
Every match looks equally urgent
Severity alone does not tell you what is likely to be exploited, so the queue is sorted by CVSS and little else.
Decisions are kept in tickets
Someone marks a CVE as not exploitable in a ticket or a spreadsheet. The next scan raises it again.

How it works with SBOM Observer

  1. 1Upload SBOMs per release

    From CI/CD with the Observer CLI, or by upload for supplier software.

  2. 2Components are matched

    Against OSV, GitHub Advisories and NVD. New advisories are matched against every stored release as they are published.

  3. 3Record the decision

    Mark a finding as not affected with a justification. It leaves the queue and can be exported as VEX.

Triage by EPSS

CVSS and EPSS sit side by side. Sort by the probability of exploitation and see the VEX analysis on each finding.

Vulnerabilities sorted by EPSS, with VEX analysis (Not Affected, Resolved) on the finding.
Vulnerabilities sorted by EPSS, with VEX analysis (Not Affected, Resolved) on the finding.

Thresholds in CI/CD

A policy on CVSS and EPSS fails the build when a release crosses it. Findings with a VEX decision of not affected do not count.

build job in CI
# Generate an SBOM for this build
observer fs -o sbom.cdx.json .
 
# Evaluate your policies. Exits non-zero on a violation
observer analyze sbom.cdx.json
 
# Upload for monitoring when the build passes
observer upload sbom.cdx.json
Failed

Library Vulnerabilities EPSS/VEX

spring-beans 5.3.17: CVE-2022-22965 with CVSS 9.8 and EPSS 0.98 is not tolerated for a library

A build fails on CVE-2022-22965 in spring-beans: CVSS 9.8 and EPSS 0.98.

Who works with it

Security operations
Start triage from the applications and releases a CVE affects.
Application owners
See the vulnerability status of their application per release, over time.
Risk managers
See CVSS, EPSS and VEX decisions together for each release.

Questions

Do you support VEX?

Yes. Record VEX decisions in SBOM Observer, import VEX from suppliers and export VEX with a release.

Which vulnerability sources do you use?

OSV, GitHub Advisories and NVD.

How is this different from blocking vulnerable packages at install?

SBOM Observer shows where a vulnerability already ships. Dependency Firewall stops packages with known CVEs from being installed. Many teams use both.

Upload an SBOM from your own build

Click through the live demo with example data, or book a demo and bring your own SBOMs.

SBOM Observer attestations: imported CycloneDX SBOMs with their status, type and component count