Open Vulnerability and Assessment Language (OVAL) is an international, information security, community standard to promote open and publicly available security content, and to standardize the transfer of this information across the entire spectrum of security tools and services. OVAL includes a language used to encode system details, and an assortment of content repositories held throughout the community. The language standardizes the three main steps of the assessment process: representing configuration information of systems for testing; analyzing the system for the presence of the specified machine state (vulnerability, configuration, patch state, etc.); and reporting the results of this assessment. The repositories are collections of publicly available and open content that utilize the language.

How does it work?

This site collects OVAL(Open Vulnerability and Assessment Language) definitions from several sources like Mitre, Red Hat, Suse, NVD, Apache etc and provides a unified, easy to use web interface to all IT security related items including patches, vulnerabilities and compliance checklists.

You can view full details of oval definitions, which is not possible at any other public web site. Other similar web sites just display comments about the definitions but here you can view exactly what you should look for to verify a vulnerability or a patch. Without itsecdb.com it is almost impossible to view details of an OVAL definition without getting lost in several xml files, definition documentation, xml schemas etc.

itsecdb is fully integrated with www.cvedetails.com so you can easily navigate between CVE, product and OVAL definition details. Most of the definitions, whenever cpe or vulnerability mappings are possible, are mapped to products defined by cvedetails.com to increase usability.

You can also browse or search for items used in oval definitions like file names, rpm packages, AIX patch numbers etc, so you can easily find all patches or vulnerabilities related to any file. For example you can view list of all patches, vulnerabilities and compliance checks related to mshtml.dll here.

Supported OVAL versions and schemas

www.itsecdb.com is not dependant on a specific OVAL schema version since it just displays the data defined in the xml files. It does not process or evaluate OVAL definitions as an OVAL compatible tool, scanner etc, would do. OVAL definitions are displayed almost as is, only some test,object etc names are simplified to make them more human readable/user friendly. For example "RPM version" string is displayed instead of evr_string etc.

If you think that there is an error about the definitions please contact admin @ [this domain]

OVAL Definitions By Referenced Objects

