1. Severity - roughly defined as in the article
2. Occurrence - How probable will this bug happen in the field? How many users would be impacted? How much support will be needed for this issue? Low - Only some very special workflows or mainly dev work impacted. Medium - Some regular users. High - Many regular users.
3. Reproducibility - How often will the bug occur when we follow the steps. Low - Single occurrence or difficult to reproduce Medium - Erratic behavior, thread problems High - It will almost always happen.
Then a PO can set a prio and give the ticket the status "will not fix" or "to be analyzed". The dev team then takes the bug and does a time boxed (1 day max) first analysis and comes back with an effort estimate of how big the issue it's too fix. Then a PO can reprioritize and set the status to "to be fixed" or not.