I am trying to figure out when a vulnerability justifies and out of cycle 
update to our Tomcat installations. After determining if we are vulnerable then 
determining the risk but our security group focuses on the CVSS score. With the 
Tomcat reports not including one I have little to go by. Is there a rough 
mapping of your “Severity” and a range of CVSS scores? Today I need to know is 
“Severity: important” a high enough risk to justify an out of cycle update of 
our Tomcat installations?

Darryl Baker, GSEC, GCLD  (he/him/his)
Sr. System Administrator
Distributed Application Platform Services
Northwestern University
4th Floor
2020 Ridge Avenue
Evanston, IL  60208-0801
[email protected]<mailto:[email protected]>
(847) 467-6674<tel:+18474676674>

Reply via email to