Concept · 7 min read
What is a vulnerability?
What has to be true before a 'finding' is a finding?
A vulnerability is a reachable weakness that enables a specific harm. Missing any of those three parts and you have a configuration observation, not a finding.
Three parts, always
- Weakness: a defect in design, implementation, configuration or behaviour.
- Reachability: an attacker position that can actually exercise it.
- Impact: a harm someone cares about — data, availability, integrity, money, trust.
Classes rather than payloads
Learn the classes; payloads go out of fashion. Input handling, authentication and session, authorisation, cryptography, configuration, business logic, dependency risk. Every specific issue is an instance of one of these.
Vulnerability vs exploit vs risk
A public exploit raises likelihood, not automatically impact. Conversely, an elegant bug with no path is still a weakness worth fixing and rarely urgent.
text
vulnerability : unauthenticated endpoint returns other tenants' records exploit : a concrete method that demonstrates it risk : likelihood x impact, given your exposure and controls
Disclosure, briefly
- Report to the owner first, with reproduction steps and no data you did not need.
- Agree a timeline before publishing anything; coordination is what makes disclosure responsible.
- If you find real personal data, stop and report. Keep testing that endpoint for more.
Check your understanding
Answer before expanding. If you cannot explain it in one sentence, the section above needs a re-read.
A CVE affects your version but the vulnerable feature is not enabled. Report it?Q1
Yes as an inventory item, no as a finding; the reachability element fails. State exactly why.
What makes 'missing security headers' weak as a finding?Q2
Impact. Unless you can show the specific harm the missing header would prevent in this application, it is a hardening suggestion.
Where this shows up
Tools in the directory whose commands assume this knowledge.