<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: openVuln API /advisories/&amp;lt;oval|cvrf&amp;gt;/all/ does not return all results in Services Discussions</title>
    <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572696#M253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Aidan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just published the OVAL definition for that vulnerability today. It is posted at the &lt;A href="https://tools.cisco.com/security/center/ovalListing.x" title="https://tools.cisco.com/security/center/ovalListing.x"&gt;OVAL Repository&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and should also be available via the API.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thank you!&lt;/P&gt;&lt;P&gt;OMar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 24 Sep 2016 21:38:59 GMT</pubDate>
    <dc:creator>Omar Santos</dc:creator>
    <dc:date>2016-09-24T21:38:59Z</dc:date>
    <item>
      <title>openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572690#M247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;openVuln API does not return all results. For example, the advisory "cisco-sa-20080326-pptp" is not present in both /advisories/oval/all and /advisories/cvrf/all results. Could you please help?&lt;/P&gt;&lt;DIV data-url="https://communities.cisco.com/discussion/create.jspa?containerType=14&amp;amp;question=true&amp;amp;containerID=5291&amp;amp;subject=openVuln%20API%20does%20not%20return%20all%20results.%20For%20example,%20the%20advisory%20%22cisco-sa-20080326-pptp%22%20is%20not%20present%20in%20both%20advisories/oval/all%20and%20advisories/cvrf/all%20results.%20Could%20you%20please%20help?" style="display: none;"&gt;836&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2016 17:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572690#M247</guid>
      <dc:creator>Andrei Batyrov</dc:creator>
      <dc:date>2016-05-12T17:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572691#M248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I looked into this a bit and experienced similar results. Playing around with other API calls, I noticed there are no advisories listed with severity "High" after 2010. Hopefully someone from PSIRT team can shed more light on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jun 2016 20:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572691#M248</guid>
      <dc:creator>eckelcu</dc:creator>
      <dc:date>2016-06-03T20:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572692#M249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OVAL definitions are supported for&amp;nbsp; &lt;STRONG&gt;high&lt;/STRONG&gt; and &lt;STRONG&gt;critical&lt;/STRONG&gt; &lt;SPAN style="font-size: 13.3333px;"&gt;Cisco IOS advisories that starting&lt;/SPAN&gt; from 2010.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Omar Santos&lt;/P&gt;&lt;P&gt;PSIRT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jun 2016 21:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572692#M249</guid>
      <dc:creator>Omar Santos</dc:creator>
      <dc:date>2016-06-03T21:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572693#M250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Omar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrei&lt;/P&gt;&lt;DIV data-url="https://communities.cisco.com/message/217352" style="display: none;"&gt;1130&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jun 2016 00:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572693#M250</guid>
      <dc:creator>Andrei Batyrov</dc:creator>
      <dc:date>2016-06-04T00:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572694#M251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Omar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just checked, there's 1882 CVRF and 81 OVAL vulnerabilities available through openVuln API, totaling 1963 vulnerabilities which is even more than it can be found on the official web page &lt;A href="http://tools.cisco.com/security/center/publicationListing.x" title="http://tools.cisco.com/security/center/publicationListing.x"&gt;Security Advisories and Alerts&lt;/A&gt; - 1948 vulnerabilities. Great progress! Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2016 15:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572694#M251</guid>
      <dc:creator>Andrei Batyrov</dc:creator>
      <dc:date>2016-08-11T15:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572695#M252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Omar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;forgive my ignorance but should - &lt;SPAN style="font-size: 10pt;"&gt;c&lt;/SPAN&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSansLight; font-size: 12px;"&gt;isco-sa-20160916-ikev1 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;be found within the oval API. considering it's both created after 2010 and a high cisco vulnerability. Oval looks great, would be keen to use!!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Sep 2016 09:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572695#M252</guid>
      <dc:creator>aidan.houlihan11</dc:creator>
      <dc:date>2016-09-24T09:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572696#M253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Aidan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just published the OVAL definition for that vulnerability today. It is posted at the &lt;A href="https://tools.cisco.com/security/center/ovalListing.x" title="https://tools.cisco.com/security/center/ovalListing.x"&gt;OVAL Repository&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and should also be available via the API.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thank you!&lt;/P&gt;&lt;P&gt;OMar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Sep 2016 21:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572696#M253</guid>
      <dc:creator>Omar Santos</dc:creator>
      <dc:date>2016-09-24T21:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572697#M254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Omar. Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will vulnerabilities be posted on the oval repository immediately after they’re found in the future? Or is it better to go with the CVSR api, as that appears to be showing all vulnerabilities at the time of posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Aidan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;http://www.vodafone.co.nz/&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aidan Houlihan&lt;/P&gt;&lt;P&gt;Discover Graduate&lt;/P&gt;&lt;P&gt;Graduate Programme&lt;/P&gt;&lt;P&gt;Vodafone New Zealand Ltd.&lt;/P&gt;&lt;P&gt;Mobile: +64 27 391 2468&lt;/P&gt;&lt;P&gt;Email: aidan.houlihan@vodafone.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lambton House, 160 Lambton Quay, Wellington, New Zealand&lt;/P&gt;&lt;P&gt;vodafone.co.nz &amp;lt;http://www.vodafone.co.nz&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This message and any files or documents attached are confidential and may also be legally privileged, protected from disclosure and/or protected by other legal rules. It is intended only for the individual or entity named. If you are not the named addressee or you have received this email in error, please inform the sender immediately, delete it from your system and do not copy or disclose it or its contents or use it for any purpose. Thank you. Please also note that transmission cannot be guaranteed to be secure or error-free.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Sep 2016 19:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572697#M254</guid>
      <dc:creator>aidan.houlihan11</dc:creator>
      <dc:date>2016-09-25T19:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: openVuln API /advisories/&lt;oval|cvrf&gt;/all/ does not return all results</title>
      <link>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572698#M255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aidan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few differences on the benefits between an OVAL definition and CVRF files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CVRF files are indeed available for all published vulnerabilities at the moment of publication. They are automatically generated when an advisory is published.&lt;/LI&gt;&lt;LI&gt;OVAL definitions are supported for IOS and IOS-XE high and critical vulnerabilities and they include affected versions and configuration checks. The OVAL standard is designed to do a full assessment of an impact of a vulnerability. &lt;/LI&gt;&lt;LI&gt;CVRF files do not include configuration checks and complete coverage of all versions affected by a given vulnerability. CVRF was not originally designed as OVAL, it is basically just an XML representation of the advisory and it currently has some limitations for remediation assessment and product family. Just as an FYI, the CVRF standard will go over a major update very soon and it is being transitioned from ICASI to the &lt;A href="https://www.oasis-open.org/"&gt;OASIS&lt;/A&gt; (&lt;A href="https://www.oasis-open.org/" title="https://www.oasis-open.org/"&gt;https://www.oasis-open.org/&lt;/A&gt;) standards body, as we speak. A new technical committee will be created within the next couple of months to enhance the standard and include better support for product and version enumeration. More details to come soon.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 12:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/services-discussions/openvuln-api-advisories-lt-oval-cvrf-gt-all-does-not-return-all/m-p/3572698#M255</guid>
      <dc:creator>Omar Santos</dc:creator>
      <dc:date>2016-09-26T12:22:59Z</dc:date>
    </item>
  </channel>
</rss>

