SAP has a CVE dispute rate of exactly 100%. Just as a fun fact. It gets worse when you look deeper into hardware vendors, where they mark things as fixed even though they aren't. And Debian as a feature frozen distribution has sooo many tags that are similar to "code diverged too much from upstream", yet they mark the CVEs as fixed; even though they are still affected and the old code from 6 years ago on exploitdb still works.
That is what led me to building a vulnerability scraper that scrapes and correlates all linux security trackers, and rates them with a confidence value (with Debian obviously having the lowest) in order to be able to discover those issues that have been correctly tagged, deployed and fixed in other distros (e.g. Arch Linux).
> They had Mcafee's DLP deployed organization wide(...)
Holy shit, that's like every sysadmin's nightmare. I feel for you, man. With a pentester's voice I always like to say that the biggest castle walls are useless when you have an ADFS server running inside it. A lot of DMZ approaches are useless because they underestimate the attack surface of their core IAM infrastructure.