Newer Version Available
Using Software That Has Known Vulnerabilities
Using software that has documented common vulnerabilities and exposures (CVE) related
to your use cases is a security vulnerability. If your solution has known vulnerabilities, test
and deploy security patches as soon as they’re available. If your solution uses software that
has CVE-documented vulnerabilities unrelated to your use cases, prepare false positive
documentation.
Hackers are quick to attack disclosed software vulnerabilities. Most vendors provide patches or updates for vulnerabilities discovered in their software. To find out if your solution uses software with known vulnerabilities, check the Common Vulnerabilities and Exposures (CVE) database.
Apply all patches or updates related to your solution’s use cases. If the vulnerabilities are unrelated to your use cases, document them as false positives. Explain why it's safe for your solution to use the vulnerable software. Our security review team uses this information when deciding whether to approve the software for use in your solution. Learn more in False Positives.