# Deepinfo Score: Low Integrity Impact

CVEs whose Deepinfo score has a low integrity impact on the vulnerable system.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-integrity/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs whose Deepinfo score has a low integrity impact on the vulnerable system.

Example 12 of 22 in **Filters › Deepinfo Score** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` · `operator` `eq`

`enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` is the impact on the integrity of the vulnerable system, in the Deepinfo score (`enrichment.vdeep_metric`: the CVSS metric Deepinfo uses for the CVE, from the newest CVSS version it has).

`eq` matches the exact value `LOW`.

In the response, look at `results[].enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` |
| `filters.must[0].type` | body | `eq` |
| `filters.must[0].value` | body | `LOW` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity",
        "type": "eq",
        "value": "LOW"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown; results[].enrichment.cwe[].capec_id: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 60531,
  "results": [
    {
      "id": "CVE-2015-0987",
      "source_identifier": "user@hq.dhs.gov",
      "published": "2015-10-06T01:59:03Z",
      "last_modified": "2026-06-17T00:21:13Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request."
        },
        {
          "lang": "es",
          "value": "Omron CX-One CX-Programmer en versiones anteriores a 9.6, dispositivos CJ2M PLC en versiones anteriores a 2.1 y dispositivos CJ2H PLC en versiones anteriores a 1.5 confían en la transmisión de contraseña en texto plano, lo que permite a atacantes remotos obtener información sensible rastreando la red durante una petición de PLC de desbloqueo."
        }
      ],
      "references": [
        {
          "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01",
          "source": "user@hq.dhs.gov",
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        },
        {
          "url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-274-01",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Third Party Advisory",
            "US Government Resource"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "LOW",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "PARTIAL",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 5.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 10.0,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-200"
            }
          ]
        },
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-319"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "403F92B5-1ABA-43FB-B365-9E57F3EA56EE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "9.5",
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:h:omron:cj2h_plc:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "707084B1-6581-4A9B-AD22-D48B3463E4E4",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "1.4",
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:h:omron:cj2m_plc:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "FA20935F-6A90-4E8C-AFD5-A3925F2D53EE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "2.0",
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:omron:cx-programmer:*:*:*:*:*:*:*:*",
            "vendor": "omron",
            "product": "cx-programmer",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "9.5",
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:h:omron:cj2h_plc:*:*:*:*:*:*:*:*",
            "vendor": "omron",
            "product": "cj2h_plc",
            "product_type": "h",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "1.4",
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:h:omron:cj2m_plc:*:*:*:*:*:*:*:*",
            "vendor": "omron",
            "product": "cj2m_plc",
            "product_type": "h",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "2.0",
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 200,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Exposure of Sensitive Information to an Unauthorized Actor",
            "description": "The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.",
            "capec_id": [
              13,
              22,
              59,
              60,
              79,
              116,
              169,
              224,
              285,
              287
            ],
            "scope": [
              "Confidentiality"
            ],
            "impact": [
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis - Source Code"
            ]
          },
          {
            "id": 319,
            "owasptop10_2021": "A02 Cryptographic Failures",
            "name": "Cleartext Transmission of Sensitive Information",
            "description": "The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.",
            "capec_id": [
              65,
              102,
              117,
              383,
              477
            ],
            "scope": [
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Modify Files or Directories",
              "Other",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis",
              "Black Box"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.01171,
          "percentile": 0.66096,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "LOW",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-62452",
      "source_identifier": "user@oracle.com",
      "published": "2026-08-18T21:17:01Z",
      "last_modified": "2026-09-01T19:56:05Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L)."
        }
      ],
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cspuaug2026.html",
          "source": "user@oracle.com",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@oracle.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "LOW",
              "availability_impact": "LOW",
              "base_score": 9.9,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.3
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-284"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "50F409B3-21EA-4B74-9325-2D89B3E68DA6",
                  "version_start_including": "22.3",
                  "version_start_excluding": null,
                  "version_end_including": "26.6",
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 284,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Improper Access Control",
            "description": "The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.",
            "capec_id": [
              19,
              441,
              478,
              479,
              502,
              503,
              536,
              546,
              550,
              551
            ],
            "scope": [
              "Other"
            ],
            "impact": [
              "Varies by Context"
            ],
            "detection_method": null
          }
        ],
        "epss_score": {
          "epss": 0.00377,
          "percentile": 0.3159,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@oracle.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "LOW",
            "vulnerable_system_availability": "LOW",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.9,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-61237",
      "source_identifier": "user@oracle.com",
      "published": "2026-07-21T22:18:54Z",
      "last_modified": "2026-07-31T15:22:54Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina.  While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L)."
        }
      ],
      "references": [
        {
          "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
          "source": "user@oracle.com",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@oracle.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "LOW",
              "availability_impact": "LOW",
              "base_score": 9.9,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.3
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-269"
            },
            {
              "lang": "en",
              "value": "CWE-284"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*",
                  "match_criteria_id": "12D96C0E-616B-4FE3-95FE-255A5368C282",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_common_objects:9.1:*:*:*:*:*:*:*",
            "vendor": "oracle",
            "product": "peoplesoft_enterprise_fin_common_objects",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "9.1",
            "affected_versions_last": "9.1"
          }
        ],
        "cwe": [
          {
            "id": 284,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Improper Access Control",
            "description": "The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.",
            "capec_id": [
              19,
              441,
              478,
              479,
              502,
              503,
              536,
              546,
              550,
              551
            ],
            "scope": [
              "Other"
            ],
            "impact": [
              "Varies by Context"
            ],
            "detection_method": null
          },
          {
            "id": 269,
            "owasptop10_2021": "A04 Insecure Design",
            "name": "Improper Privilege Management",
            "description": "The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.",
            "capec_id": [
              58,
              122,
              233
            ],
            "scope": [
              "Access Control"
            ],
            "impact": [
              "Gain Privileges or Assume Identity"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00377,
          "percentile": 0.3159,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@oracle.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "LOW",
            "vulnerable_system_availability": "LOW",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.9,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [Deepinfo Score: Complete Confidentiality Impact](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-confidentiality/)
- [Deepinfo Score: Low Availability Impact](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-vulnerable-system-availability/)
- [Deepinfo Score: User Interaction Required](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-user-interaction/)
- [Deepinfo Score: Exploit Maturity Attacked](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-exploit-maturity/)
- [Deepinfo Score: High Privileges Required](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-privileges-required/)
- [Deepinfo Score: Diffuse Value Density](/reference/vulnerability/search/examples/enrichment-vdeep-metric-cvss-data-value-density/)
