[OVAL REPOSITORY] AffectedType Multiple Products

David Solin solin at jovalcm.com
Thu May 26 10:13:27 EDT 2016

Hi Jerome,

The OVAL schema permits multiple product tags to be children of an affected tag (and also, multiple affected tags to be children of a metadata tag).  Therefore I quite agree, multiple product references should not appear in a single product tag.

You should feel free to fork, fix and create a pull request for these definitions.

Best regards,
—David Solin


> On May 23, 2016, at 9:16 AM, Jerome Athias <athiasjerome at gmail.com> wrote:
> Hi,
> Sorry to bother you, especially while I'm not contributing much.
> I know that "The schema places no restrictions on the values that can
> be assigned, potentially leading to many different representations of
> the same value." for Product
> But to increase the utility of the product element (while I'm using it
> :p), I would see value avoiding 2 products in the same tag.
> i.e.:
> oval:org.mitre.oval:def:7152
> <product>python2.4 python2.5</product>
> oval:org.mitre.oval:def:13443
> <product>zope2.10/zope2.9</product>
> I do understand that would maybe need splitting the Definition.
> Intent is not complaining or adding extra work regarding old definitions.
> Your contributions are much appreciated and very valuable! So thanks for that
> Best regards
> ...
> _______________________________________________
> OVAL_Repository mailing list
> OVAL_Repository at lists.cisecurity.org
> http://lists.cisecurity.org/mailman/listinfo/oval_repository_lists.cisecurity.org


More information about the OVAL_Repository mailing list