github.com/CycloneDX/sbom-utility@v0.16.0/examples/cyclonedx/VEX/Use-Cases/Case-7/README.md (about) 1 # VEX Use Case 7 2 3 | All Products | All Versions | Single Vulnerability | Not Affected | 4 | --- | --- | --- | --- | 5 6 A VEX states that CVE-2020-25649 is not exploitable in any current version of any product made by a 7 particular software developer. 8 9 This example is a bit vague, as the metadata section doesn't state which component (product) the VEX is 10 applicable to. In reality, the VEX should be applied to a group of SBOMs, similar to [Case-6](../Case-6).