What was the genesis of the CWE initiative?
Lacking common characterization of exploitable software constructs presented one of the major challenges to realizing software assurance. As part of our Software Assurance public-private collaboration efforts, the federal government has provided the sponsorship of those aspects for which industry and academia lacked incentives to fund on their own, but would use once matured. With the release of CWE version 1.7., the schema stabilized to the point that tool vendors, testers, and the software security industry could easily adopt and use CWE. More than 47 products and services already use CWE in a compatible manner; yet more work is needed to put CWE into more routine use by all software stakeholders.