`problemTypes` and CWE are recommended, but not required. If `type` is 'CWE' then require `cweId` and test the value with a reasonable regex (something like ^CWE-[0-9]{2,5}).