---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Solution Management

# Vulnerability Solution Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 17 minutes to read  
Automatically correlate vulnerabilities in your environment with solutions that can remediate them. Identify remediation actions that apply to your vulnerabilities and prioritize them by the greatest reduction in
vulnerability risk.

## Vulnerability Solution Management {#vuln-solution-mgmt__section_xwl_qpz_qhb}

Security and IT teams often spend significant time researching vulnerability findings to identify the most effective treatments for their environment. Given the volume and complexity of vulnerabilities in large organizations,
translating vulnerability findings into remediation tasks is a manual, time-consuming, and error-prone process.

With Vulnerability Solution Management, you can automatically correlate your vulnerability findings with solutions that remediate them. Identify software patches, configuration updates, and other controls that have the highest impact
for your organization without the manual overhead.

## Vulnerability Solution Management requirements {#vuln-solution-mgmt__section_vdn_lr2_tmb}

Vulnerability Solution Management is a feature available within the Vulnerability Response application. Vulnerability Solution Management requires a separate subscription.

For more information about getting entitlements for applications from the ServiceNow Store, see [Get entitlement for a Security Operations product or application](https://www.servicenow.com/docs/oEh8SW2y0YHvcOMuL39Pew "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements."). See [Install the Solution Management for Vulnerability Response application](https://www.servicenow.com/docs/f4zOYK7Zs3VKVntOBY31aQ "Before you can use the Solution Management for Vulnerability Response feature of Vulnerability Response in your instance, you must complete the installation of the Vulnerability Solution Management application. This application is available as a separate subscription in the ServiceNow Store.") for more information about installing the application after you have downloaded it onto your instance.

After installation, Vulnerability Solution Management provides you access to the Microsoft Security Response Center and the Red Hat solution data from within Vulnerability Response.  
Note:  
You can configure both solution applications from within the Setup Assistant. See [Configure installed solution integrations for Vulnerability Solution Management using Setup Assistant](https://www.servicenow.com/docs/UYbH9rWrAAPNfSiVYcZG5g "After you install the Vulnerability Solution Management application, you can configure your vulnerability solution providers using Setup Assistant.").

See [Microsoft Security Response Center Solution Integration](https://www.servicenow.com/docs/azhzKki9~~9vaBvwD4NrzQ "Review and implement proposed remediation solutions provided by the Microsoft Security Response Center Solution Integration.")
and [Red Hat Solution Integration](https://www.servicenow.com/docs/C5UtHtUzRbi6kj397b6SEQ "You can review and implement proposed remediation solutions provided by the Red Hat Solution Integration in the Vulnerability Response application.") for more information on the imported solutions.

## Available versions {#vuln-solution-mgmt__section_cl2_tkb_qgb}

For the most current version of Vulnerability Solution Management, verify you have the most current version of Vulnerability Response installed.  
{#vuln-solution-mgmt__AvailableVersions__entry__3}

| Release version of Vulnerability Solution Management | Compatible versions of Vulnerability Response | Release Notes |
|-|-|-|
| Vulnerability Solution Management v10.3 | Vulnerability Response v18.0 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498) |
[ ]

{#vuln-solution-mgmt__AvailableVersions}

## About solutions and supersedence {#vuln-solution-mgmt__section_vjz_ztf_rhb}

A superseded update is a complete replacement of a previous release or releases. For example, a hot fix update may be superseded by a Service Pack. Solutions are related to vulnerabilities. Solutions can also relate to other
solutions in a supersedence chain. Solutions address vulnerabilities in preceding solutions as well as they're cumulative. Vulnerability Solution Management automatically associates vulnerabilities from preceding solutions with superseding solutions. If an older vulnerability is found, any higher superseding solution can address it, but the highest
supersedence solution is preferred, as it's the most comprehensive.

## Potential versus Preferred Solutions {#vuln-solution-mgmt__section_vdw_skh_zhb}

A potential solution is one that could address a vulnerability. Vulnerabilities often have many potential solutions. A preferred solution is the single solution targeted for remediating a vulnerability or vulnerable item (VI).
It communicates intention and enables more detailed deployment metrics.

## Preferred Solutions {#vuln-solution-mgmt__section_hsd_qlh_zhb}

Vulnerability Solution Management automatically sets the most effective solution (Preferred Solution) for the detected vulnerability based on highest supersedence when only one highest supersedence solution
exists. If more than one highest supersedence exists for the vulnerability, no value is set. In Vulnerability Response, a Preferred Solution is the Microsoft Security Response Center or Red Hat solution with the highest supersedence derived from the solutions associated with the vulnerability.  
Preferred Solution values can be set on the vulnerable item or the vulnerability. When set directly on the vulnerability, all vulnerable items associated with the vulnerability inherit that solution. Change the Preferred Solution values for multiple vulnerable items using the bulk edit feature. When bulk edited, only the Preferred Solution on the vulnerable item is updated as setting the Preferred solution at the vulnerability entry level would set the Preferred solution for all new VIs going forward. Bulk editing only applies to current vulnerable items.  
Note:  
If multiple highest supersedence solutions exist for a vulnerability, Preferred Solution values at the vulnerability level are cleared, as that solution depends on the affected asset. When multiple highest supersedence solutions exist for a vulnerability, set a Preferred Solution on the vulnerable item. You can set a different solution using the Lookup list on the Vulnerable Item form.

All preferred solutions for the vulnerable items in a remediation task are in a related list on the Remediation Task record.  
Not all solution imports result in full data refreshes. The supersedence process is updated when:

* A vulnerable item is created.
* Data has changed on an active VI.  
  Note:  
  Starting with v22.0 of Vulnerability Response, the solutions aren't queued in the above two cases.
* A new mapping is created for a third-party entry with the CVE.
* New solution data was released since last import, an existing solution is updated.
{#vuln-solution-mgmt__ul_ff3_vfk_vhb}  
Starting with v24.0.6 of Vulnerability Response, you can ingest solutions from scanners in addition to vendor solutions. The remediation data from scanners such as Tenable, Qualys, and Microsoft TVM is leveraged to create the solutions. These scanner solutions are imported using the following integrations:

* Tenable.sc Plugin Integration
* Tenable.io Plugin Integration
* Qualys Knowledge Base (Backfill)
* Microsoft TVM Machine Vulnerabilities Integration (Full Import)
* Microsoft TVM Machine Vulnerabilities Integration (Delta Import)

{#vuln-solution-mgmt__ul_ty4_yq4_2dc}When the vulnerability integrations run, a payload of remediation information is created before processing third-party entries. For Tenable and Qualys, the remediation data is received at the vulnerability or third-party entry level. Conversely, for Microsoft TVM, solutions are created at the detection level, enabling a direct population of preferred solutions on the vulnerable items without the need for further processing. These solutions are created based on this remediation information and processed as needed. On processing, the preferred solution is populated on the vulnerabilities and rolled down to the vulnerable items. The preferred solution is populated in the following order:

* Manual selection: If you select a solution manually, it isn't overridden.
* Vendor solutions (Microsoft, RedHat, CVRF, and CSAF imports): If you don't select a solution manually, the vendor solution is selected automatically.
* Latest solutions (if enabled): If there are multiple higher-superseding solutions available for a vulnerability, then the preferred solution field remains empty. In such cases, if you enable the property sn_vul.latest_solutions, the latest higher supersedence vendor solution is populated as the preferred solution.
* Scanner Bulletin solutions (if enabled): If you don't select a solution manually or vendor solutions are unavailable, the Preferred solution field is populated with the scanner solutions provided there's a single scanner solution. You must enable the property sn_vul.populate_scanner_solutions to populate the scanner solutions.
{#vuln-solution-mgmt__ul_s4q_ygs_2dc}  
Figure 1. Solutions from multiple sources This example illustrates the selection of a solution when multiple solutions are available from different sources. In this case, there are two solutions for a vulnerability - one from a vendor and another from a scanner. Since the solution VS0116107 is received from a vendor (Redhat), which has higher preference, it is selected as the preferred solution.  
Figure 2. Solutions from same vendor This example illustrates the selection of a solution when multiple solutions are available from the same vendor (Redhat in this case). If the sn_vul.latest_solutions property is enabled and no other vendor solutions are available for a specific vulnerability, these solutions are processed, populating preferred solutions on the vulnerabilities and subsequently on vulnerable items. If you enable the property sn_vul.latest_solutions, the latest solution is selected as the preferred solution.Figure 3. Solutions from same scanner This example illustrates the selection of a solution when only one scanner solution is available from the scanners. If the sn_vul.populate_scanner_solutions property is enabled, the solutions are processed, populating the preferred solutions on the vulnerabilities and subsequently on the vulnerable items. If there are multiple scanner solutions, the Preferred solution field is left empty due to ambiguity.

## Enhancing solution management and performance optimization {#vuln-solution-mgmt__section_jvg_lz1_cbc}

Solutions are sourced from multiple integrations, including Microsoft and Redhat. Microsoft issues monthly updates and maintains a chain of dependencies, designating preferred solutions for vulnerabilities. Other integrations use a different update approach and do not maintain a dependency
chain. Historically, a graph-based approach was utilized to manage solution precedence and identify the highest superseding solutions, which were recommended as preferred solutions for vulnerabilities. However, due to the
time-intensive nature of graph construction, only Microsoft solutions were included in this process. To improve performance, starting from v22.0 of Vulnerability Response, the method utility.processNonGraphSolutions() is invoked by the Process Vulnerability Solutions Metrics Queue scheduled job. This method processes solutions
from integrations other than Microsoft.  
The Process Vulnerability Solutions Metrics Queue scheduled job aggregates solutions from all sources, consolidates solutions from NVD to third-party entries, determines preferred solutions on vulnerabilities, and refreshes remediation status metrics. Updates to remediation status metrics occur in the following situations:

* When the preferred solution is updated on the vulnerabilities
* When VITs are created or deleted
* When a VIT import is completed

{#vuln-solution-mgmt__ul_vhp_l5d_cbc}To further optimize processing, the Update status column has been added to the Vulnerability Solution table. If only remediation status needs updating, without recalculating or rolling up preferred solutions, the Update status is set to true. This limits the number of solutions placed in the queue, saving time and compute resources. After queued solutions are processed, the job identifies those with Update status set to true and updates remediation status metrics accordingly.  
The scheduled job Process Vulnerability Solution Metrics Queue evaluates and populates preferred solutions on vulnerability records imported from the Microsoft Security Response Center (MSRC) and Red Hat Solution Integration. It also applies solution roll-downs to affected vulnerable items and recalculates remediation status metrics on the corresponding solution records. This process may result in extensive resource consumption given the processing scale, which can include hundreds of thousands of vulnerabilities. Initial solution ingestion or large data imports may substantially extend execution duration, but in steady state with a reduced queue, processing time decreases. Starting from v26.5.3 of Vulnerability Response, the Process Vulnerability Solution Metrics Queue scheduled job has been divided into two separate jobs to enable concurrent processing:

* Process Vulnerability Solution Metrics Queue - Chained Solutions
* Process Vulnerability Solution Metrics Queue - Non-chained Solutions
{#vuln-solution-mgmt__ul_rs3_zjm_s3c}This segmentation allows for parallel execution of solution processing tasks, enhancing throughput.  
Chained Solutions job: Solutions from the Microsoft Security Response Center (MSRC) are released as monthly incremental updates connected by supersedence chains; each update supersedes its predecessors. The Chained Solutions job uses a directed graph traversal to identify the highest-superseding solution, which is set as the preferred solution for the relevant vulnerability records and vulnerable items.  
Note:  
The complex graph traversal may require significant processing time, especially for instances with a high volume of vulnerability data.Non-chained Solutions Job: Solutions from Red Hat and other supported providers do not form supersedence chains and do not need graph-based processing. These are handled via a streamlined process managed entirely by the Non-chained Solutions job.  
To access remediation status metrics, go to the Vulnerability Solution \[sn_vul_solution\] table, select a specific vulnerability solution, and open the Remediation Status tab. This tab reports the following fields:{#vuln-solution-mgmt__table_z5k_bwb_glb__entry__2}

| Field | Description |
|-|-|
| Preferred Solution Targets - Remediation status for VIs for which this is the preferred solution ||
| Vulnerable items | Number of active (non-closed) vulnerable items for which this solution is preferred for remediation. This count excludes deferred vulnerable items. |
| Remaining CIs | Number of CIs associated with one or more active vulnerable items for which this solution is preferred for remediation. This count excludes deferred vulnerable items. |
| Total VIs | Number of active and closed vulnerable items for which this solution is preferred for remediation. This count excludes deferred vulnerable items. |
| Total CIs | Number of CIs associated with one or more active and closed vulnerable items for which this solution is preferred for remediation. This count excludes deferred vulnerable items. |
| % VIs remediated | Percent complete for vulnerable item (VI) remediation. Applies to VIs for which this solution is preferred. This count excludes deferred vulnerable items. |
| % CIs remediated | Percent complete for CI remediation. Applies to VIs for which this solution is preferred. This count excludes deferred vulnerable items. |
| Preferred Solution Targets (Includes Deferred) - Remediation status for VIs, including deferred, for which this is the preferred solution ||
| Vulnerable items | Number of active (non-closed) vulnerable items for which this solution is preferred for remediation. |
| Remaining CIs | Number of CIs associated with one or more active vulnerable items for which this solution is preferred for remediation. This count excludes deferred vulnerable items. |
| Total VIs | Number of active and closed vulnerable items for which this solution is preferred for remediation. |
| Total CIs | Number of CIs associated with one or more active and closed vulnerable items for which this solution is preferred for remediation. |
| % VIs remediated | Percent complete for vulnerable item (VI) remediation. Applies to VIs for which this solution is preferred. |
| % CIs remediated | Percent complete for CI remediation. Applies to VIs for which this solution is preferred. |
| Potential Solution Targets - Remediation status for all VIs with a vulnerability related to this solution ||
| Vulnerable items | Number of active (non-closed) vulnerable items for which this solution is a potential solution for remediation. This count excludes deferred vulnerable items. |
| Remaining CIs | Number of CIs associated with one or more active vulnerable items for which this solution is a potential solution for remediation. This count excludes deferred vulnerable items. |
| Potential Solution Targets (Includes Deferred) - Remediation status for all VIs, including deferred, with a vulnerability related to this solution ||
| Vulnerable items | Number of active (non-closed) vulnerable items for which this solution is a potential solution for remediation. |
| Remaining CIs | Number of CIs associated with one or more active vulnerable items for which this solution is a potential solution for remediation. |
[Table 1. Remediation Status metrics]

{#vuln-solution-mgmt__table_z5k_bwb_glb}  
Additionally, the availability of a preferred solution for vulnerabilities and VITs must be ensured to remediate the vulnerabilities. However, in situations where multiple higher superseding solutions exist for a vulnerability, a preferred solution isn't populated due to ambiguity. To address this scenario, an approach is implemented that involves running the processing logic and populating the preferred solution when it's available. In cases where there's only one higher superseding solution, it's populated as the preferred solution. When multiple higher superseding solutions are present, the preferred solution field remains empty. However, the aim is to populate the highest superseding solution, which is published as the latest, as the preferred solution. To achieve this, a system property sn_vul.latest_solutions is introduced. By default, this property is set to false. If you want to enable the capability of populating the latest solutions as the preferred solution when no preferred solution is available, then you can enable this property. Once enabled, the Solution type column is updated in the vulnerability table with the following options:

* Preferred: When the preferred solution is populated
* Latest: When no preferred solution is available, the latest solution from the set of highest superseding solutions is selected based on the date published value. The field to be selected as the latest solution can be customized using the sn_vul.latest_solutions system property. By default, the value is set to "date published," but it can be changed to "last modified" to select the solution based on the last modified column in the solutions.
* Manual: When the preferred solution type is updated manually. The precedence for this type of solution is the highest.
{#vuln-solution-mgmt__ul_fyv_5fb_cbc}

In certain scenarios, the preferred solution on a vulnerable item (VIT) may differ from the preferred solution on the corresponding vulnerability. This occurs when the preferred solution is manually updated on a VIT and not on
the vulnerability. In such cases the Solution type field is hidden on the VIT.

## What Vulnerability Solution Management does {#vuln-solution-mgmt__section_wq1_qpz_qhb}

* Automatically associates new vulnerable items (VITs) and remediation tasks with solutions during Microsoft Security Response Center Solution Integration
  and Red Hat Solution Integration import.

  MSRC solutions are associated with the latest bulletin the solution appears in.
* Automatically associates vulnerable items and remediation tasks with solutions when vulnerability records are associated manually with solutions.  
  Note:  
  Vulnerable items manually reassigned to another solution aren't automatically updated with solution changes at the vulnerability level.
* MSRC: Creates supersedence chains during import that you can view in the solution's related list.
* Indicates whether a solution is a highest-supersedence solution or not.
* Lists the Solution Risk score associated with each solution to provide you with the biggest opportunities for risk reduction.
* Maintains Remediation Status for solutions on third party Vulnerability Entries, Remediation Tasks, and Vulnerability Solution
  records so you can track remediation progress.

  It contains:
  * Vulnerable item counts by percent remediated, for those VIs with Preferred Solutions, with and without those VIs in the Deferred state.
  * Configuration Item (CI) counts by percent remediated, for those VIs with Preferred Solutions, with and without those VIs in the Deferred state.
  * Vulnerable item counts by percent remediated, for those VIs with Potential Solutions, with and without those VIs in the Deferred state.
  * Configuration Item counts by percent remediated, for those VIs with Preferred Solutions, with and without those VIs in the Deferred state.
  {#vuln-solution-mgmt__ul_kfq_qhs_vhb}
{#vuln-solution-mgmt__ul_rzd_ybb_2hz}

## What you can do with Vulnerability Solution Management {#vuln-solution-mgmt__section_a3t_c5f_rhb}

* Create, update, view, or delete solutions associated with vulnerabilities, so that you can track vulnerability solutions that aren't covered by third-party solution content. Solution Integration with the Rapid7 Data warehouse is not supported.
* Associate third-party vulnerabilities and NVD entries with a solution record.
* Remove and reassociate vulnerable items and remediation tasks with a solution.
* View the Preferred Solution applicable to a given vulnerability on the vulnerability and vulnerable item forms.
* View a Preferred Solutions related list on remediation task forms that list all the solutions that have been preferred by at least one active VI within that group.
* View the Remediation Status details on a solution that show the risk reduction associated with deploying the Preferred Solution on vulnerability, vulnerable item, remediation tasks, and solution forms.
* View vulnerabilities applicable to a given solution on the solution form.
* MSRC: View the superseding solutions for a given solution on a vulnerability, to find the latest update to deploy, or an earlier, more focused, efficient update.
* View lists of solutions sorted for different characteristics.
  * All: Solutions sorted by Date published and Number.
  * MSRC: Highest Supersedence: Solutions with active, non-deferred vulnerable items. Sorted by Highest supersedence, Date published, and Number.
  * With Vulnerable Items: Solutions with active, non-deferred vulnerable items. Sorted by Highest supersedence or Preferred, Risk Score, and Number. If deployed, the top entries in the list provide the largest risk reduction for the assets in your environment.
  {#vuln-solution-mgmt__ul_od4_f4s_vhb}
{#vuln-solution-mgmt__ul_mcg_ybb_2hb}

## Solution record Risk score and Risk rating {#vuln-solution-mgmt__section_qrt_rpz_qhb}

Note:  
The Solution record Risk score and Risk rating are distinct from those fields used for vulnerabilities, vulnerable items, and remediation tasks.

The Solution record Risk score is a weighted calculation based on the vulnerable item Risk score and a count of active vulnerable items with this solution as their
Potential Solution. The solution Risk score provides an estimation of the reduction in risk that the solution is expected to accomplish.  
The solution record Risk score is calculated as follows:

* It starts by taking 85% of the highest or maximum Risk score of an active vulnerable item with that potential solution.
* The solution record Risk score then tabulates the total number of vulnerable items with that potential solution. For each range of the number of vulnerable items, it adds some points and arrives at a total.
  * 0--09 vulnerable items adds no points
  * 10--99 vulnerable items adds 5 points
  * 100--999 vulnerable items adds 10 points
  * 1000 and beyond vulnerable items adds 15 points

  {#vuln-solution-mgmt__ul_jy1_kqz_qhb}

  For example, for a vulnerable item Risk score of 80, the Solution record Risk score would start at 68. If there were 200 active total vulnerable items with that potential
  solution, then the final Solution Risk score would be 78.
{#vuln-solution-mgmt__ul_dm4_2qz_qhb}

The Solution record Risk rating separates the Solution record Risk score into ranges from Critical to None. Solution Risk rating rates the risk reduction for
the vulnerable items that this solution remediates.  
Up to v16.1 of Vulnerability Response, risk ratings separated the resulting Solution Risk score into the following ranges:

* 1 --- Critical (90+ Solution Risk score)
* 2 --- High (70-89 Solution record Risk score)
* 3 --- Medium (30-69 Solution record Risk score)
* 4 --- Low (1-29 Solution record Risk score)
* 5 --- None (0 Solution record Risk score)
{#vuln-solution-mgmt__ul_n1w_brz_qhb}  
Starting from v16.1 of Vulnerability Response, risk ratings separate the resulting Solution Risk score into the following ranges for Solution Management:

* 1 --- Critical (90+ Solution Risk score)
* 2 --- High (70-89 Solution record Risk score)
* 3 --- Medium (40-69 Solution record Risk score)
* 4 --- Low (1-39 Solution record Risk score)
* 5 --- None (0 Solution record Risk score)
{#vuln-solution-mgmt__ul_syv_dcr_tsb}

## Use Cases {#vuln-solution-mgmt__section_wtc_5mh_zhb}

View the deployment progress status of a current patch cycle using the highest-supersedence module, sorted by date.

View highest value solutions using the With Vulnerable Items module, sorted by risk score.  
Solution lists communicate key solution details, risk scores, and deployment metrics. Use Risk score and active VI counts for prioritization. See which solutions in the current patch cycle aren't progressing, possibly an indication of a missed deployment prerequisite.  
Note:  
Add %VIs remediated(percent_nd_pref_vis_remediated) from the personalize List Columns menu for remediation progress on the Vulnerability Solutions form.
* **[Microsoft Security Response Center Solution Integration](https://www.servicenow.com/docs/azhzKki9~~9vaBvwD4NrzQ)**   
  Review and implement proposed remediation solutions provided by the Microsoft Security Response Center Solution Integration.
* **[Red Hat Solution Integration](https://www.servicenow.com/docs/C5UtHtUzRbi6kj397b6SEQ)**   
  You can review and implement proposed remediation solutions provided by the Red Hat Solution Integration in the Vulnerability Response application.
* **[Rapid7 solution management](https://www.servicenow.com/docs/~GU0v2iTFeiflAqthqOzBw)**   
  Solutions are known remediations that are imported into your Rapid7 Vulnerability Integration from either the Rapid7 data warehouse or Rapid7 InsightVM. Rapid7 data warehouse imports both solutions and superseding solutions. With Rapid7 InsightVM, you get solutions as part of the Rapid7 Vulnerable Item Integration - API.
* **[Generic framework to ingest data from any solution vendor](https://www.servicenow.com/docs/CRD0lgfm3dyqv3TMP6D~QQ)**   
  A generic framework for solution intelligence integration is available to support ingestion of data in different file formats from solution vendors. These formats speed up information exchange and processing and facilitate the sharing of critical security-related information in a standardized reporting format.

