Vulnerability Impact
Go from a CVE to the applications and releases that ship the affected component. Sort by CVSS and EPSS, and record VEX decisions on the finding so they do not come back on the next scan.
A CVE names a package and nothing else
A scanner reports a CVE in a package. It does not say which of your applications ship that package, in which releases, or whether someone already decided it does not apply.
- Finding affected applications takes a search
- Tracing a package to the releases that ship it means going through build output by hand.
- Every match looks equally urgent
- Severity alone does not tell you what is likely to be exploited, so the queue is sorted by CVSS and little else.
- Decisions are kept in tickets
- Someone marks a CVE as not exploitable in a ticket or a spreadsheet. The next scan raises it again.
How it works with SBOM Observer
1Upload SBOMs per release
From CI/CD with the Observer CLI, or by upload for supplier software.
2Components are matched
Against OSV, GitHub Advisories and NVD. New advisories are matched against every stored release as they are published.
3Record the decision
Mark a finding as not affected with a justification. It leaves the queue and can be exported as VEX.
Triage by EPSS
CVSS and EPSS sit side by side. Sort by the probability of exploitation and see the VEX analysis on each finding.

Thresholds in CI/CD
A policy on CVSS and EPSS fails the build when a release crosses it. Findings with a VEX decision of not affected do not count.
# Generate an SBOM for this buildobserver fs -o sbom.cdx.json .# Evaluate your policies. Exits non-zero on a violationobserver analyze sbom.cdx.json# Upload for monitoring when the build passesobserver upload sbom.cdx.json
Library Vulnerabilities EPSS/VEX
spring-beans 5.3.17: CVE-2022-22965 with CVSS 9.8 and EPSS 0.98 is not tolerated for a library
Who works with it
- Security operations
- Start triage from the applications and releases a CVE affects.
- Application owners
- See the vulnerability status of their application per release, over time.
- Risk managers
- See CVSS, EPSS and VEX decisions together for each release.
Questions
Do you support VEX?
Yes. Record VEX decisions in SBOM Observer, import VEX from suppliers and export VEX with a release.
Which vulnerability sources do you use?
OSV, GitHub Advisories and NVD.
How is this different from blocking vulnerable packages at install?
SBOM Observer shows where a vulnerability already ships. Dependency Firewall stops packages with known CVEs from being installed. Many teams use both.
More SBOM Observer use cases
All use cases- SBOM ManagementCollect CycloneDX and SPDX from CI/CD and suppliers, and keep one SBOM record per release.
- Regulatory ComplianceKeep SBOM, VEX and policy results per release for CRA, NIS2 and DORA.
- Software InventoryOne inventory of components and releases across internal and supplier software.
- M&A and Due DiligenceReview an acquisition target or new vendor from its SBOMs.
Upload an SBOM from your own build
Click through the live demo with example data, or book a demo and bring your own SBOMs.
