CWE: a common software weakness with standardized descriptors that could catalyze a vulnerability. CVE: a known public vulnerability associated with 3rd party software. Mark flies solo to explain the difference and how CVEs can help us at the prioritization stage, and how CWEs come into play further on the left as we correlate data across tools.
Resources
More tactics for AppSec Success are coming at AppSecCon 2023
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.