I am trying to figure out when a vulnerability justifies and out of cycle update to our Tomcat installations. After determining if we are vulnerable then determining the risk but our security group focuses on the CVSS score. With the Tomcat reports not including one I have little to go by. Is there a rough mapping of your “Severity” and a range of CVSS scores? Today I need to know is “Severity: important” a high enough risk to justify an out of cycle update of our Tomcat installations?
Darryl Baker, GSEC, GCLD (he/him/his) Sr. System Administrator Distributed Application Platform Services Northwestern University 4th Floor 2020 Ridge Avenue Evanston, IL 60208-0801 [email protected]<mailto:[email protected]> (847) 467-6674<tel:+18474676674>
