Uploaded image for project: 'Red Hat Advanced Cluster Security'
  1. Red Hat Advanced Cluster Security
  2. ROX-30427

Add EPSS field in policy engine and in UI

    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • Hide
      An EPSS (Exploit Prediction Scoring System) policy criterion is now available to construct new, or modify existing policies.

      You can focus on CVE's which are more likely to get exploited by
      creating an affective policy that combines severity and EPSS value (CRITICAL and EPSS > 50%).
      Show
      An EPSS (Exploit Prediction Scoring System) policy criterion is now available to construct new, or modify existing policies. You can focus on CVE's which are more likely to get exploited by creating an affective policy that combines severity and EPSS value (CRITICAL and EPSS > 50%).
    • Enhancement
    • Yes

      Outcome

      EPSS is now available from the scanner. Customers would like to use it for new policies (for example RFE-7958 )

      Scope

      Add a new EPSS Probability criterion to policy engine, API and UI

      This is an IMAGE related criterion

       

      Attribute Value
      Policy JSON name EPSS
      Attribute (UI Short name) EPSS
      Long Name (UI) EPSS probability
       data type presented in ui  Percentage .  Allowed values:  whole number integers [0 ..100] inclusive
      Criterion Operation use our standard for such fields  : ( >, >=, =, <=, <)
       
      Default value (including example) (ex. 75%)
      UI Description EPSS (Exploit Prediction Scoring System) provides a numerical score to predict the likelihood of a vulnerability being exploited in the wild
      Location in UI After NVD CVSS
       
      Documentation In addition to UI description, add a ink to where EPSS is documented https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.8/html/operating/managing-vulnerabilities 

       

       

      ===

      From an RFE: 

      Having EPSS field in security policies, would help be able to create a policy which combines severity and EPSS value (CRITICAL and EPSS > 50%).

      Customer would like to be able use the EPSS value in their policies, so that they can create a policies such as:

      "Critical CVE and EPSS value greater than 50%" or
      "CVSS greater than 8 and EPSS greater than 25%".

      This would help the customer:
      1.Be able to focus on CVE's which are more likely to get exploited
      2.Save Time and Money with creating an affective policy which combines severity and EPSS value (CRITICAL and EPSS > 50%).

        1. image-2025-08-01-14-49-38-303.png
          39 kB
          Boaz Michaely
        2. image-2025-08-01-15-07-27-731.png
          17 kB
          Boaz Michaely

              vwilson@redhat.com Van Wilson
              bmichael@redhat.com Boaz Michaely
              Boaz Michaely Boaz Michaely
              ACS Core Workflows
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated: