Mitre Standard Eases Vulnerability Research

Mitre Standard Eases Vulnerability Research

Written By
Dennis Fisher
Dennis Fisher
Dec 16, 2002
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Mitre Corp. last week announced the availability of a new language designed to make it easier for researchers to define and explain vulnerabilities found in software.

Known as OVAL (Open Vulnerability Assessment Language), the budding standard is built on Mitres well-known description of vulnerabilities, the CVE (Common Vulnerabilities and Exposures) database. Whenever a researcher finds a flaw in a software application, he or she can submit it to Mitre for consid- eration. If the organization finds it is a new vulnerability, it is assigned a CVE candidate number, which identifies it as a unique problem.

Queries to the database are written in SQL and can be incorporated into security tools or reviewed by hand. Every OVAL query is based on one or more CVE entries.

The query development process involves the submission of draft OVAL queries to a public forum that includes system administrators, software vendors and security analysts for review, debate and refinement. The result is a mass of vulnerability data available to the entire Internet community.

“OVAL solves the consistency problem,” said Matthew Wojcik, senior information security engineer at Mitre, based in Bedford, Mass.

“The queries provide a base line for performing vulnerability assessments, and each query reflects the combined expertise of the broadest-possible collection of security and system administration professionals,” Wojcik said.

Mitre is a not-for-profit company that works closely with the government on security and other issues.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.