The following table outlines a vulnerability’s timeframe for resolution by severity type for our appAPP.
Severity | CVSS Score | Timeframe for resolution |
---|---|---|
Critical | CVSS v3 >= 9.0 | Must be fixed within 4 weeks of being reported or triaged. |
High | CVSS v3 >= 7.0 | Must be fixed within 6 weeks of being reported or triaged. |
Medium | CVSS v3 >= 4.0 | Must be fixed within 8 weeks of being reported or triaged. |
Low | CVSS v3 < 4.0 | Must be fixed within 25 weeks of being reported or triaged. |
...