Invicti - ServiceNow Application Vulnerable item source severity change by SecCommon System user
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-15-2025 06:32 AM
When AVIT is created from Invicti, the source severity was High. But then it shows user SecCommon System updated Risk Score and Risk Rating from High to Medium. When checked we could see changes in Vulnerability table sn_vul_app_vul_entry. It too shows sam user has updated the record. When checked with Invicti, the source severity is high at there end. Can anyone tell what does it mean by updated by SecCommon System user. Does source severity gets change after creation and from where it gets changed?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-16-2025 07:30 AM
Source severity is not changed but is translated into a target severity based on severity mapping shipped for Invicti - so for source severity there would be a target severity for that entry. check the columns on the on app vul entry from Invicti using Show XML to understand better.
At AVIT level, the risk calculators kicks in and use the various params to stamp risk score on AVITs and then based on the risk score the risk rating gets stamped (this is based on how vuln calculators have been configured). These are computed via BRs on the AVIT table.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-17-2025 06:13 AM
@MiravTMehta - What we saw when AVIT is created from Invicti it shows user as VR.System and the based on the mapping of invicti severity(High) servicenow risk rating(High) and risk score is set. But next day the risk rating got modified (from High to Medium) by user SecCommon System in 'AVIT' table and same thing in 'Vulnerability' table- sn_vul_app_vul_entry.
In 'sn_vul_app_vul_entry' xml, all 3 fields -normalized severity, source normalized severity and source severity shows "Medium".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi @prit123
Can you open a case-task on servicenow portal with above information, so that our team can look into it. Please do add additional logs / values coming from payload that could help bring this issues to closure.
Thanks
Mirav T. Mehta
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Friday
We did raise a case . Also the state change in Invicti doesn't reflect in ServiceNow. There is one mapping table in which the Fixed (Confirmed) state in Invicti mapped to closed. But it didn't change the state in ServiceNow.
