ISTQB Mock App

Vulnerability

A vulnerability is a weakness in software, hardware, or processes that can be exploited by a threat to compromise security.

Official definition
ISTQB Official Glossary Definition
A weakness in a component, system, procedures, or controls that could allow for a successful security attack.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Vulnerability?

Vulnerabilities may allow attackers to gain unauthorized access, modify data, disrupt services, or perform other malicious actions.

Security weakness: Creates opportunities for attacks.

Risk factor: May be exploited by threats.

Requires mitigation: Should be identified and addressed promptly.

Real World Example

A regulated product team is preparing a release where Vulnerability appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.

The risk is that the team treats Vulnerability as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.

The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Vulnerability and similar ideas.

The page becomes useful in practice because Vulnerability is connected to a specific testing decision, not memorized as a detached definition.

Practice Questions

Question 1

Which statement BEST describes Vulnerability in the context of ISTQB terminology?

Question 2

A tester needs to explain Vulnerability to a non‑technical stakeholder. Which approach is MOST appropriate?

Test your knowledge with real ISTQB-style questions

You’ve learned Vulnerability. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams