Common Weakness Enumeration (CWE) Compatibility program allows a service or a product to be reviewed and registered as officially "CWE-Compatible" and "CWE-Effective". The program assists organizations in selecting the right software tools and learning about possible weaknesses and their possible impact.
In order to obtain CWE Compatible status a product or a service must meet 4 out of 6 requirements, shown below:
There are 56 organizations as of September 2019 that develop and maintain products and services that achieved CWE Compatible status.9
Some researchers think that ambiguities in CWE can be avoided or reduced.10
As of 4/16/2024, the CWE Compatibility Program has been discontinued.11
"CWE - About CWE". at mitre.org. http://cwe.mitre.org/about/index.html ↩
"CWE - Frequently Asked Questions (FAQ)". cwe.mitre.org. Retrieved 2023-09-21. https://cwe.mitre.org/about/faq.html#cwe_sponsor ↩
"Vulnerabilities | NVD CWE Slice". National Vulnerability Database. https://nvd.nist.gov/vuln/categories ↩
Goseva-Popstojanova, Katerina; Perhinschi, Andrei (2015). "On the capability of static code analysis to detect security vulnerabilities". Information and Software Technology. 68: 18–33. doi:10.1016/j.infsof.2015.08.002. https://linkinghub.elsevier.com/retrieve/pii/S0950584915001366 ↩
"CWE - About - CWE History". cwe.mitre.org. Retrieved 2025-02-18. https://cwe.mitre.org/about/history.html ↩
"CWE Version 4.15 Now Available". Mitre Corporation. Retrieved 17 October 2024. https://cwe.mitre.org/news/archives/news2024.html#july16_CWE_Version_4.15_Now_Available ↩
Bojanova, Irena (2014). "Bugs Framework (BF): Formalizing Software Security Weaknesses and Vulnerabilities". samate.nist.gov. /w/index.php?title=Irena_Bojanova&action=edit&redlink=1 ↩
"CWE - CWE-121: Stack-based Buffer Overflow (4.15)". cwe.mitre.org. Retrieved August 5, 2024. https://cwe.mitre.org/data/definitions/121.html ↩
"CWE - CWE-Compatible Products and Services". at mitre.org. https://cwe.mitre.org/compatible/compatible.html ↩
Paul E. Black; Irena V. Bojanova; Yaacov Yesha; Yan Wu (2015). "Towards a "Periodic Table" of Bugs". National Institute of Standards and Technology. https://www.nist.gov/publications/towards-147periodic-table148-bugs ↩
"CWE-Compatible Products and Services". Common Weakness Enumeration. Archived from the original on 2025-01-07. https://web.archive.org/web/20250107144449/https://cwe.mitre.org/compatible/compatible.html ↩