What is VDR?
A VDR (Vulnerability Disclosure Report) reports the known vulnerabilities in a product and the supplier's analysis of them
A VDR (Vulnerability Disclosure Report) is a report in which a supplier accounts for the known vulnerabilities in a product and in the components the product contains.
The term comes from the US standard NIST SP 800-161, which deals with supply chain risk management. It describes the VDR as a way for a supplier to show that the vulnerabilities in the components listed in an SBOM have been assessed completely.
What a VDR contains
For each vulnerability, a VDR reports:
- which vulnerability it is, for example a CVE number
- which component and which product version are affected
- the supplier's analysis of how the vulnerability affects the product, or why it does not
- what the supplier plans to do about it
NIST also recommends that the report is published in a portal that customers have access to, and that it is signed and timestamped.
VDR, SBOM and VEX
The three documents answer different questions:
| Document | Question |
|---|---|
| SBOM | Which components does the product contain? |
| VDR | Which known vulnerabilities are in the product, and how do they affect it? |
| VEX | Is the product affected by this vulnerability, yes or no? |
A VDR gives the whole picture, including the vulnerabilities that do affect the product. VEX is mainly used to say which vulnerabilities do not, so that the recipient can filter them out.
VDR and CVE
A CVE is an identifier for a single vulnerability, with a short description that applies regardless of product. A VDR concerns a specific product and says what the vulnerability means for it. What is a vulnerability? describes CVE and other identifiers.
Formats
CycloneDX supports expressing a VDR, either in the same document as the SBOM or in a separate one. The Scale SBOM framework describes content requirements for SBOM, VEX and VDR.
References
- NIST Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - 2022doi.org
This publication provides a comprehensive guide to supply chain risk management practices for systems and organizations.