---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability

# Vulnerability {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.

The weakness or defect is in the requirements, designs, or implementations of the code found in a software or hardware component. This weakness is directly exploited to negatively impact the confidentiality, integrity, or availability
of that system.

CVE is a list of information security vulnerabilities and exposures that provides common names for publicly known problems \[CVE\].

For example, if a piece of malware exploits CVE-2015-12345, a Malware object could be linked to a Vulnerability object that references CVE-2015-12345.
* **[Define Vulnerability](https://www.servicenow.com/docs/Oij3STyJH8a59apMKMq1YQ)**   
  Define vulnerability as a weakness or defect in a software or hardware component that attackers exploit.
* **[Create a CWE record](https://www.servicenow.com/docs/vcJGKmvwiKTg6fvD0cT~Sw)**   
  Create a Common Weakness Enumeration (CWE) record to represent a weakness identified in a system or product, and link it to relevant vulnerabilities.
* **[Create a Product](https://www.servicenow.com/docs/OCjFRL120iwsoViUu9qCCg)**   
  Create New Product feature allows you to record the product's version, vendor, and classification details, to ensure products are accurately linked to vulnerabilities and related records.
* **[Create a Vendor to a Vulnerability](https://www.servicenow.com/docs/a7dl3EpUyH3Lup6wU1RwLQ)**   
  Use this feature to create a vendor. Once created, you can associate the vendor to a product or link them to a vendor comment.
* **[Create Remediations](https://www.servicenow.com/docs/1k9AJ9JkZqaUmwgrPfv6Gg)**   
  Create a remediation record to document a fix or workaround for a vulnerability affecting a specific product.
* **[Access the Vulnerability Entities](https://www.servicenow.com/docs/Yqt1FpU6Hjq_I~uj5GbnuQ)**   
  The Vulnerability Intelligence Center (VIC) uses the following entities to store and organize vulnerability, product, and vendor intelligence data.
* **[Fetch Vulnerability Data](https://www.servicenow.com/docs/rCc4zmLMjwu4WMum5vKP3g)**   
  Fetch vulnerability related data such as configuration items, vulnerable entries, and business context.

**Related concepts**   

* [Observables](https://www.servicenow.com/docs/mtj0sOYtYVd9ZZ2fpM_hMg "Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.")
* [Indicators](https://www.servicenow.com/docs/B69N6Wdc7W0nI0ks7FqyYA "Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names.")
* [Threat Entities](https://www.servicenow.com/docs/_5DGFV0RjbonAf2KRyZj9g "The Threat Entities module provides structured records used to manage threat intelligence objects in the TISC. These records align with STIX domain object concepts and help standardize how threat activity is documented and analyzed.")
* [Other Objects](https://www.servicenow.com/docs/NqecVRly6M6WQnxqn9Ixkw "Define and manage data classifications within TISC.")
* [Working with Reports in TISC](https://www.servicenow.com/docs/hPkrs37a6HKieeOtSSJxKg "The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.")
* [MITRE-ATT\&CK Repository](https://www.servicenow.com/docs/Y50sAsUgKJ4SYkPZ2Obf~g "The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested.")
* [Relationships Objects](https://www.servicenow.com/docs/Kffra0ZJbg3rrW_AS5wO_g "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.")
* [Potential Relationships](https://www.servicenow.com/docs/dc1NAg3gI_TtywVl9FXRcg "The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.")
* [Vulnerability relationship mapping](https://www.servicenow.com/docs/ibGmPhY7zIIuaKPXbv8OzA "Use many-to-many (M2M) relationship records to map connections between vulnerabilities and other entities.")  
**Related tasks**   

* [Define RSS Feeds](https://www.servicenow.com/docs/izYjMP8Xu6MPWNyfL5cJxw "A threat intelligence feed is a real time, continuous data stream that gathers information related to cyber risks or threats. RSS Feeds provides an easy way to stay up to date with your favorite websites, such as blogs or latest cyber security news.")

