A vulnerability is a weakness in systems, processes, or components that can be exploited by threat actors. It covers causes, attack vectors and potential impacts on confidentiality, integrity, or availability. The concept supports identification, assessment and prioritization of security gaps and appropriate mitigations.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
A vulnerability is an exploitable weakness in software, systems, or processes that can threaten confidentiality, integrity, or availability.
The term comes from information security and became established in practice through systematic weakness classifications such as MITRE CWE and risk catalogues such as the OWASP Top 10.
A vulnerability is a property that opens an attack path under certain conditions. Risk arises from the interaction of weakness, reachable target, and possible impact.
A flawed property can be misused.
Conditions make exploitation possible.
An attack can harm security objectives.
The vulnerability concept helps teams identify, prioritize, and remediate security risks systematically.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.