The Critical Vulnerability Management (CVM) data feed provides details on CVM findings along with several other data sets.
Schemas:
Other data sets:
- Assets – Information about IPs and domains associated with findings.
- Asset Event – How assets are attributed to findings.
- Vulnerability Catalog – Detailed metadata on vulnerabilities in your Vulnerability Intelligence subscription.
- Vulnerability Occurrence – Associates vulnerabilities to findings.
Data Structure Diagram
Data Solutions data feeds are optimized for relational databases. Use the structure conveyed in the following diagram to make the best use of entity relationships within the Critical Vulnerability Management (CVM) Intelligence data feed:
Schemas
Finding Details
| Field | Description |
|---|---|
String [ |
The temporary unique identifier for this finding. |
String [ |
The unique identifier of the company. |
String [ |
When the finding was first observed. |
Boolean |
true = This finding affects the rating. |
String |
The country where the asset attributed with this finding is located. |
String |
The country code where the asset attributed with this finding is located. |
String [ |
The date when this finding stops impacting the rating if nothing else changes. |
String |
The finding grade. |
String |
The source of evidence for the finding. It may be from an IP address, domain, IP/domain combination, or port. |
String [ |
The first time the finding was observed. |
String |
A reason code for why the finding does not impact on the rating. |
String |
The reason why the finding no longer impacts the rating. |
Boolean |
true = This finding has been remediated. |
String [ |
The most recent time the finding was observed. |
String |
The unique identifier of this observation. |
Integer |
The number of days it took to remediate the finding. |
String |
The risk category. |
String |
The risk vector slug name. |
String |
The risk vector name. |
String [ |
The date when this finding was first observed. |
String [ |
The date when the infection was last observed. |
String |
A stable and randomized identifier for findings. It is assigned to a finding when one or more observations with largely similar key properties occur in close succession. |
Decimal |
This finding’s Bitsight severity. |
String |
This finding’s Bitsight severity. |
Remediation Dates
| Field | Description |
|---|---|
String |
The temporary unique identifier for this finding. |
String [ |
The date and time when the finding first appeared. |
String [ |
When the finding is remediated. |
- September 11, 2024: Published.
Comments
Please sign in to leave a comment.