Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7958

Having EPSS field in security policies

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • rhacs, rhacs-policy
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Having EPSS field in security policies, would help be able to create a policy which combines severity and EPSS value (CRITICAL and EPSS > 50%).

      Customer would like to be able use the EPSS value in their policies, so that they can create a policies such as:

      "Critical CVE and EPSS value greater than 50%" or
      "CVSS greater than 8 and EPSS greater than 25%".

      This would help the customer:
      1.Be able to focus on CVE's which are more likely to get exploited
      2.Save Time and Money with creating an affective policy which combines severity and EPSS value (CRITICAL and EPSS > 50%).

              bmichael@redhat.com Boaz Michaely
              rhn-support-dalowe Daniel Lowe
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                None
                None