Components with vulnerabilities

Check ID
COMP_0001

Category

Security

Summary

A Mendix app consists of a large number of different software components: The Mendix runtime, widgets, modules, Java libraries. and JavaScript libraries. Each of these components can have known security vulnerabilities. Blue Storm maintains a central database of known security vulnerabilities. If a component is known to have a security vulnerability it is flagged in the AppControl repository.

Options

There are no options for this check. Note: The severity level set by AppControl when creating a check result is based on the CVSS score (Common Vulnerability Scoring System) of the vulnerability. The following mapping is used: 7.0-10 HIGH 4.0-6.9 MEDIUM 0-3.9 = LOW

Pass

A component does not have any known security vulnerabilities.

Fail

A component has known security vulnerabilities.

Last updated