I'll speak up in defense of the reporters: FWIW, so far my strong impression is we're hearing from independent security researchers. Right now, for us, so far (enough qualifiers yet?) the system is working for us: independent security researchers are farming reputation by finding real problems. That's not a bad thing.
And in most cases they do propose solutions, although we generally resolve the issues on our own.
There's a small percentage where we make the case that the ticket is not a real vulnerability, and then we have to grit our teeth through repeated reports of the same "vulnerability." But it's a small percentage so far.
We do typically have to reconsider the severity. The researchers understandably want to see everything as a nine...