The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Severity Ratings

Jon | Last updated: Jan 11, 2016 07:09PM UTC

I understand that the severity ratings are defined based upon the experience of your security researchers and and seeing the vulnerabilities in real applications. What I have not yet been able to identify is what exactly a High, Medium or Low actually means. If a vulnerability is identified as High, what does that mean? Does a high mean that the effort needed to exploit is trivial, and the data exposed is significant? And what would make such a vulnerability a severity of High versus a Medium? Is medium a less trivial exploit, or resulting in minimal data exposure. To help understand what I am asking, you can look at the PCI compliance Level definitions. Starting at page 5 https://www.pcisecuritystandards.org/pdfs/pci_scanning_procedures_v1-1.pdf

PortSwigger Agent | Last updated: Jan 12, 2016 08:46AM UTC