Vulnerability prioritization criteria

How XEIZE OnPrem determines priority scores for SAST, SCA, Secrets, and IaC issues.

XEIZE assigns each security issue a priority score from 0 to 100. This score is distinct from severity, which describes the issue's technical risk, and helps you decide which issues to address first.

  • Severity describes the potential technical impact of exploiting a vulnerability.
  • Priority scores combine severity with information that affects the order of remediation, such as exploitability, detection confidence, evidence of exploitation, code reachability, and the scope of credential permissions.

Priority levels

Level Score range Recommended action
Immediate 90–100 Investigate and address first because of actual exploitation or a very high potential impact.
Urgent 80–89 Treat as an important security issue and prepare a remediation plan promptly.
Soon 70–79 Manage as a priority issue and include it in planned remediation.
Review needed 0–69 Below the Top Priorities threshold, but still review according to the environment and the importance of the asset.

Criteria by scan type

Scan type Main criteria Effect on priority
SAST Impact, exploitability, detection confidence, and exposure scope Uses the score defined in each SAST rule first. When no rule score exists, calculates a base score from likelihood, impact, and precision. Vulnerabilities with greater impact and a higher likelihood of being true positives receive higher priority; code-quality and basic hardening items receive lower scores.
SCA CVSS, EPSS probability and percentile, code reachability, malicious packages, known exploitation, public exploits, ransomware, and potential for automation Uses CVSS as the base risk and incorporates attack likelihood and reachability in the current project. A high CVSS score alone does not immediately promote an issue to priority response without additional threat or reachability signals. Malicious packages or known exploitation substantially increase priority.
Secrets Credential type, permission scope, and potential impact of exposure Groups detection rules by the potential impact of the credentials. Cloud and infrastructure credentials are in the higher tier, followed by tokens for source control, artifacts, and secret-management services. Items with unclear permissions or usage, such as generic API keys, receive lower default scores.
IaC Potential for compromise caused by infrastructure configuration Scores whether an infrastructure configuration issue can lead to compromise. Docker-related IaC issues are currently capped below the Top Priorities threshold.

Order of precedence for the final score

If multiple scoring criteria apply to the same issue, the final score uses this order:

  1. A score manually set by a user
  2. A score configured in a Custom Rule
  3. The base score calculated for the scan type

An issue with a manually adjusted score or a Custom Rule score can therefore display a score different from the scan type's default calculation.

Reference criteria