WHAT IS CWE ?

CWE (Common Weakness Enumeration) is a community-developed formal list of common software weaknesses. It serves as a common language for describing software security weaknesses, a standard measuring stick for software security tools targeting these vulnerabilities, and as a baseline standard for weakness identification, mitigation, and prevention efforts. Leveraging the diverse thinking on this topic from academia, the commercial sector, and government, CWE unites the most valuable breadth and depth of content and structure to serve as a unified standard. The objective of CWE effort is to help shape and mature the code security assessment industry and also dramatically accelerate the use and utility of software assurance capabilities for organizations in reviewing the software systems they acquire or develop.

Security-Database use CVEs along the appropriate CWEs if available.

WHAT DOES IT MEAN TO BE CWE-COMPATIBLE ?

"CWE-compatible" means that a tool, Web site, database, or other security product or service uses CWE names in a manner that allows it to be cross-referenced with other products that employ CWE names. CWE-compatible means:
Security-Database is planning to create a new generation of complete XML feed to supply the next generation of SSA vulnerability Management Software. The complete XML feed will enumerate every known information on a vulnerability (CVE, CPE, OVAL ID, CVSS, CWE, CAPEC, CCE, Vendor Patchs ...)

See the CWE Web site for detailed information on how a Web site, tool, database, or other security product/service becomes compatible, and for a complete list of CWE-compatible products and services.

HOW SECURITY DATABASE USES CWE ?

Security-Database is making a declaration to be CWE compatible.

Security-Database alerts quotation are mostly based on the publicly known vulnerabilities identified on the CVE List. CVE names (also called "CVE numbers," "CVE-IDs," and "CVEs") are unique, common identifiers for publicly known information security vulnerabilities. We have extended our web development to include CWEs and CAPECs.

Each CVE name includes the following:
In order to enumerate all CWEs entries according to the CWE.mitre.org requirements documents and version, the direct link http://www.security-database.com/cwe.php get from Menu (Solution -> Security Classification) could be used.

FOR MORE INFORMATION ON CWE COMPATIBILITY ?

See the CWE Web site for detailed information on how a Web site, tool, database, or other security product or service becomes compatible, and for a complete list of CWE-compatible products and services