Re: [csaf] CVSS v2/v3 use in CVRF 1.2

From
Art Manion <>
Date
2017-04-05T02:07:20+00:00
ID
Thread
Re: [csaf] CVSS v2/v3 use in CVRF 1.2
On 2017-04-04 15:31, Mr. Stefan Hagen wrote:

> I move, that the chair of the TC shall request a ballot for a full
> majority vote from administration with the ballot question: "Every
> vuln:CVSSScoreSets element if present MUST contain zero or more
> CVSSScoreSetV2 and one or more CVSSScoreSetV3 elements" offering the
> answers "yes", "no", and "abstain".

Assuming discussion is allowed at this point...

How can a vuln:CVSSScoreSets element have more than one CVSSScoreSet?
This means a vulnerability can have two or more CVSS scores?  Can anyone
provide a use case/example?

Thanks,

 - Art