Optionaldetail?: stringOptionalfirstIssued?: TimestampThe date and time (timestamp) when the analysis was first issued.
Optionaljustification?: cdx_15.ImpactAnalysisJustificationThe rationale of why the impact analysis state was asserted.
OptionallastUpdated?: TimestampThe date and time (timestamp) when the analysis was last updated.
A response to the vulnerability by the manufacturer, supplier, or project responsible for the affected component or service. More than one response is allowed. Responses are strongly encouraged for vulnerabilities where the analysis state is exploitable.
Optionalstate?: cdx_15.ImpactAnalysisStateDeclares the current state of an occurrence of a vulnerability, after automated or manual analysis.
Detailed description of the impact including methods used during assessment. If a vulnerability is not exploitable, this field should include specific details on why the component or service is not impacted by this vulnerability.