At Salesforce, the security of our customers' data is our top priority. We understand that transparency is crucial in building and maintaining trust. To this end, we have a clear and stringent policy for disclosing security vulnerabilities through the Common Vulnerabilities and Exposures (CVE) framework.
Salesforce as a CVE Numbering Authority
Salesforce is the CVE Numbering Authority (CNA) for all Salesforce products. This means we have the authority to assign CVE identifiers to vulnerabilities for all products within the Salesforce suite of products. We work in close partnership with MITRE to issue CVEs, ensuring that our customers are informed of vulnerabilities that require their attention for remediation.
When We Publish CVEs
We carefully evaluate the benefits of issuing a CVE against the potential risks. Our goal is to minimize the risk for all customers while maintaining transparency. We recognize that public disclosure elevates the risk of alerting potential attackers. Therefore, we only issue CVEs when it is appropriate and necessary.
Salesforce publishes CVEs when remediating the vulnerability requires action from external parties, typically our customers. This includes scenarios such as patching on-premise and open-source application software.
CVE Publishing Criteria
We issue CVEs for vulnerabilities that meet both of the following criteria:
The vulnerability is rated as CRITICAL or HIGH and
Remediation of the vulnerability requires action from the customer.
Our Process
Proactive Communication: Before issuing a CVE, we proactively communicate with impacted customers. This ensures they are aware of the vulnerability and the actions they need to take to protect their data and systems.
30-Day Notification Period: We issue CVEs 30 days after these proactive communications. This period allows our customers to address the vulnerability before it is publicly disclosed, minimizing the risk of exploitation.
Customer Assurance
We want to assure our customers that we are committed to maintaining the highest security standards. Our policy is designed to protect your data while providing you with the information you need to secure your systems. We appreciate your understanding and cooperation in maintaining the security of our products and your data.
004693694

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.