On 2017-04-04 15:31, Mr. Stefan Hagen wrote:
> I move, that the chair of the TC shall request a ballot for a full
> majority vote from administration with the ballot question: "Every
> vuln:CVSSScoreSets element if present MUST contain zero or more
> CVSSScoreSetV2 and one or more CVSSScoreSetV3 elements" offering the
> answers "yes", "no", and "abstain".
Assuming discussion is allowed at this point...
How can a vuln:CVSSScoreSets element have more than one CVSSScoreSet?
This means a vulnerability can have two or more CVSS scores? Can anyone
provide a use case/example?
Thanks,
- Art