github.com/CycloneDX/sbom-utility@v0.16.0/examples/cyclonedx/VEX/Use-Cases/Case-7/README.md (about)

     1  # VEX Use Case 7
     2  
     3  | All Products | All Versions | Single Vulnerability | Not Affected |
     4  | --- | --- | --- | --- |
     5  
     6  A VEX states that CVE-2020-25649 is not exploitable in any current version of any product made by a 
     7  particular software developer.
     8  
     9  This example is a bit vague, as the metadata section doesn't state which component (product) the VEX is
    10  applicable to. In reality, the VEX should be applied to a group of SBOMs, similar to [Case-6](../Case-6).