Skip to content
brianmather edited this page Jan 10, 2014 · 13 revisions

This page provide a listing of all supported CWE identifiers, and walks users through the steps of locating and filtering vulnerabilities by CWE Identifier.

Supported CWE identifiers

A complete listing of the CWE identifiers supported by ThreadFix v1.2 (and the current set of integrated scanners) can be found by viewing [CWE 2.5] (http://cwe.mitre.org/data/index.html). ThreadFix allows for manual entry of vulnerabilities, allowing for complete coverage/support of all CWE identifiers found in [CWE 2.5] (http://cwe.mitre.org/data/index.html).

Identified vulnerabilities are mapped to CWE identifiers

Step 1: From the applications page, expand the target vulnerability type group

CWE1.2_Step1.jpg

Step 2: Select the ‘View More’ Link for the desired vulnerability.

CWE1.2_Step2.jpg

Step 3: Click on the CWE Entry URL to navigate to the to the associated CWE identifier on MITRE’s website.

CWE1.2_Step3.jpg

Filtering by CWE Identifier

Filtering vulnerability data is a feature of ThreadFix. Users can filter many criteria including CWE identifier.

Step 1: On the application page, click the 'Show Filters' link

CWE1.2_FilterbyID_Step1.jpg

Step 2: Type in the CWE ID number, click the ‘Filter’ link.

CWE1.2_FilterbyID_Step2.jpg

Step 3: Results associated with the specified CWE ID will be displayed immediately below.

CWE1.2_FilterbyID_Step3.jpg


If you're interested in another topic, here are some links:

Supported Threadfix [Dynamic Scanners] (https://github.com/denimgroup/threadfix/wiki/Dynamic-Scanners), [Static Scanners] (https://github.com/denimgroup/threadfix/wiki/Static-Scanners), [Remote Providers] (https://github.com/denimgroup/threadfix/wiki/Remote-Providers)

Supported Threadfix [Software Defect Trackers] (https://github.com/denimgroup/threadfix/wiki/Software-Defect-Trackers)

Supported Threadfix [WAF Types] (https://github.com/denimgroup/threadfix/wiki/WAF-Types)

ThreadFix Plugins: Zap Plugin, [Burp Plugin] (Burp-Plugin), [Eclipse IDE Plugin] (Eclipse-IDE-Plugin), [IntelliJ IDEA Plugin] (IntelliJ-IDEA-Plugin)

Threadfix [Vulnerability Merging] (https://github.com/denimgroup/threadfix/wiki/Vulnerability-Merging)

Threadfix [Vulnerability Format] (https://github.com/denimgroup/threadfix/wiki/Vulnerability-Format)

Clone this wiki locally