Document:
The Missing Manual: CVRF 1.1

Draft (A preliminary unapproved sketch, outline, or version.)

Details

Submitted By Mr. Omar Santos on 2016-11-22 9:11 pm UTC

Publication Type

None at this time.

Group / Folder

OASIS Common Security Advisory Framework (CSAF) TC / Contributions

Modified by

Not modified.

Copy

This document is not a copy.

Technical Contact

None at this time.

Download Count

198

Download Agreement

None at this time.

Description

In this whitepaper you will learn about some of the design decisions behind the 1.1 release of the Common Vulnerability Reporting Framework. Particular attention is paid to explaining some of the required elements and the Product Tree. After those tasty tidbits, we will convert a recent Cisco security advisory into well-formed and valid CVRF document. To close, you are treated to some of the items on the docket for future versions of CVRF. It bears mentioning that this paper is not meant to be an exhaustive explanation of the CVRF schemata. It is a rather capricious, if somewhat disorganized look at some outliers that aren't fully explained elsewhere. It is assumed the reader has a working knowledge of the Common Vulnerability Reporting Framework and of XML.