---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Explore

# Exploring Application Vulnerability Response {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Application Vulnerability Response

Application Vulnerability Response (AVR) is a component of the ServiceNow Vulnerability Response application designed to manage vulnerabilities in custom software applications throughout their development lifecycle.
AVR imports vulnerability data from internal and external sources, including Common Weakness Enumeration (CWE) and third-party scanners.
It correlates this data with applications in your Configuration Management Database (CMDB) to identify and manage application vulnerable items (AVITs).
Show full answer Show less  

## How It Works

AVR processes imported vulnerability data by matching it against CMDB application records. When a match is found, an AVIT is created to track the vulnerability. The system supports integration with multiple third-party scanners and uses automated rules and calculators to prioritize, assign, and remediate vulnerabilities effectively. Vulnerabilities are monitored in the Vulnerability Manager and IT Remediation Workspaces.

## Supported Vulnerability Data Types

* **Dynamic Application Security Testing (DAST):** Scans running applications by simulating attacks and identifying vulnerabilities via URL locations.
* **Static Application Security Testing (SAST):** Analyzes source code at rest, identifying vulnerabilities by file and line number.
* **Interactive Application Security Testing (IAST):** Detects vulnerabilities during application runtime using combined automated and manual interactions.
* **Software Composition Analysis (SCA):** Identifies vulnerabilities in open source components starting with Vulnerability Response version 19.0.
* **Penetration Testing:** Supports manual assessment requests to identify and address application weaknesses.
* **Software Bill of Materials (SBOM):** Enables upload of component data to identify open source vulnerabilities.

## Key Features

* **Third-Party Integrations:** Supports importing vulnerability data via shared APIs and integrates with multiple security tools available on the ServiceNow Store.
* **CI Lookup Rules:** Automate matching vulnerabilities to CMDB configuration items.
* **Assignment Rules:** Automatically assign AVITs based on user groups or custom scripts.
* **Risk Calculators:** Prioritize vulnerabilities using customizable impact and severity filters.
* **Severity Mapping:** Standardizes severity ratings based on CWE data for consistent risk assessment.
* **Remediation Target Rules:** Define expected remediation time frames to monitor and manage AVIT resolution.
* **Reporting:** Provides insights into security posture, remediation trends, and critical applications or business units.

## Application Vulnerable Items (AVITs)

AVITs represent vulnerabilities linked to specific scanned applications within the CMDB. They track the latest scan results and remain associated until marked as fixed or the application is removed. AVITs can be managed and viewed within the Application Vulnerability Response modules to support remediation workflows.

## User Roles and Collaboration

AVR supports collaborative management through defined user groups and roles including App-Sec Manager, Application Security Champion, and Developer. These roles help organize responsibilities for vulnerability identification, prioritization, and remediation.

## Integration with ServiceNow CSDM and Security Operations

AVR and related Vulnerability Response applications leverage and contribute to the Common Service Data Model (CSDM) tables, enhancing integration with other ServiceNow products and enabling comprehensive security operations management.  
Application vulnerabilities are vulnerabilities on your custom software applications that are scanned throughout the application's development life cycle.

## Overview of Application Vulnerability Response and available versions {#app-vuln-mgmt__section_e1c_h52_flb}

Application Vulnerability Response (AVR) is the part of the Vulnerability Response application that processes application vulnerabilities.  
{#app-vuln-mgmt__AvailableVersions__entry__2}

| Release version | Release Notes |
|-|-|
| Vulnerability Response v23.0 Vulnerability Response v22.0 Vulnerability Response v21.0 Vulnerability Response v20.0 Vulnerability Response v19.0 Vulnerability Response v18.2 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498) |
[Table 1. Available versions]

{#app-vuln-mgmt__AvailableVersions}

## How it works {#app-vuln-mgmt__section_mgp_hd3_vzb}

Vulnerability data is imported from internal and external sources, such as the Common Weakness Enumeration (CWE) or third-party integrations. After data is imported, it is
compared to application data in your Configuration Management Database (CMDB) and processed in the Application Vulnerability Response application. If a match exists between imported application vulnerability data and data in your CMDB, an application vulnerable item (AVIT) is created.  
The Application Vulnerability Response includes the following key features:

* Integrate with supported third-party scanners to import vulnerability data.
* Compare application vulnerability-related data and determine if application vulnerabilities are found in an application.
* Prioritize, remediate, and manage application vulnerable items (AVIT)s. Each application vulnerability represents a vulnerability entry in the CWE or third-party libraries.
* Starting with version 18.0 of Vulnerability Response, you can monitor and remediate AVITs in the Vulnerability Manager Workspace and IT Remediation Workspace respectively. For more information, see [Vulnerability Manager Workspace](https://www.servicenow.com/docs/WOWpVKcYQ5ZdCQLiQyqxlQ "The Vulnerability Manager Workspace enables vulnerability managers and analysts to monitor the vulnerabilities and misconfigurations that they care the most about and decide strategically which vulnerabilities they send to IT teams to fix.") and [IT Remediation Workspace](https://www.servicenow.com/docs/D9BRjYnOom_ib04Kx1nqmA "IT teams can save time resolving IT-related vulnerabilities by easily creating change requests, rescanning vulnerable items, and submitting exception requests from the IT Remediation Workspace.").
* Correlate Application Vulnerability Response data using calculators and libraries to help you perform the following tasks.
  * Create application vulnerable items automatically using CI Lookup Rules. During import, third-party vulnerabilities are associated to a CWE to create an AVIT.
  * Create assignment rules to automate application vulnerable item assignments.
  * Use calculator groups to determine business impact, specify varying conditions using filters, apply simple calculations, or use a script.
  * Create remediation target rules that define the expected time frame for remediating application vulnerable items so you can monitor upcoming remediation activities.
  {#app-vuln-mgmt__ul_wc4_qpc_cdb}
* Relate a single third-party vulnerability to multiple CWE entries and find the primary CWE for a vulnerability to help you determine risk. For more information on the Primary CWE, see [Application Vulnerability fields](https://www.servicenow.com/docs/UUPa2sPm9ukaZrr7ZoC9NA "Vulnerabilities are created automatically when records are downloaded from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE) or third-party integrations. NVD and CWE are stored under Libraries in Vulnerability Response or under Vulnerabilities in Application Vulnerability Response.").
* Use CWE records that are downloaded from the CWE database or imported from third-party integrations for reference to help you decide if you must escalate a vulnerability. Each CWE record also includes an associated knowledge article that describes the weakness.
{#app-vuln-mgmt__ul_j2b_jpc_cdb}

Use Application Vulnerability Response to follow the flow of information, from integration through investigation, and then on to resolution.

## Types of imported vulnerability data {#app-vuln-mgmt__section_ikg_rrl_hlb}

Application Vulnerability Response supports the following types of imported application vulnerability data.  
Note:  
Prior to v19.0, SAST, SCA, IAST, and penetration testing data was not ingested and may account for differences between what is shown within Veracode, Fortify, and Invicti and what appears in Application Vulnerability Response.  

Dynamic Application Security Testing (DAST)
:   DAST scans find vulnerabilities application by sending input to your applications and monitoring its responses while they are running. This approach might imitate an outside attack. During dynamic scanning, a running
    service (URL) is scanned for vulnerabilities. Vulnerability results include a URL location of a discovered vulnerability.

Static Application Security Testing (SAST)
:   SAST scans review the source code of applications at rest and help you find vulnerabilities in the way you've written your code. The SAST scan takes place on non-compiled source code and so it exists independently of
    any application service. Returned results include a file and line number location of a discovered vulnerability.

Interactive Application Security Testing (IAST)
:   IAST scans detect software vulnerabilities by interacting with the program while it is running. Human observation, automated tests, and sensors are used in combination to interact with the application to locate
    vulnerabilities.

Software Composition Analysis (SCA)
:   Starting with v19.0 of Vulnerability Response, you can ingest Software Composition Analysis (SCA) vulnerabilities. SCA vulnerability data to helps you identify weaknesses in the open source software being used in your software
    applications.

Penetration testing
:   You configure penetration test assessment requests in Application Vulnerability Response to help you understand where your application weaknesses are and what you can do to fix them.

Software Bill of Materials
:   Upload Software Bill of Materials (SBOM) data to identify vulnerabilities in your open source components. See [Exploring Software Bill of Materials](https://www.servicenow.com/docs/_y9uO7ds0dogOuzyG6~gOA "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") for more information.

## Use cases {#app-vuln-mgmt__section_egg_sfb_vzb}

Some of the following DAST use cases are supported:

* Relate each vulnerability from scan results to some kind of cmdb_ci (child class).
* Relate DAST scan results to an existing application when there is a record in the CMDB from Discovery or a third-party integration.
* Relate DAST scan result to a newly inserted scanned application when a new Application has not previously been identified and/or stored in the CMDB.
* Store DAST scan results for a CMDB when you manage your applications in a product other than ServiceNow®.
* Store DAST scan results for a CMDB if you have previously customized for some other purpose.
* Create an application for Source code repository manually.
{#app-vuln-mgmt__ul_pyc_gx2_flb}  
Some of the supported SAST use cases are supported:

* Relate each vulnerability from scan results to some kind of cmdb_ci (child class).
* Create a CI for Source code repository manually.
* Store SAST scan results that are without a related Application Service.
{#app-vuln-mgmt__ul_e2q_hx2_flb}

## Third-party integrations {#app-vuln-mgmt__section_w42_bwh_vzb}

The third-party integrations supported by Application Vulnerability Response are available as a separate applications in the ServiceNow Store. See [Integrating Application Vulnerability Response with other applications](https://www.servicenow.com/docs/cRDocCPn6dbTJn39OULXfA "Vulnerability Response includes support for third-party integrations.") for more information.

## Key features {#app-vuln-mgmt__section_xk2_m2b_vzb}

* A shared API imports DAST, SAST, IAST, and SCA data and manual pen testing results. See [Penetration testing](https://www.servicenow.com/docs/JrzytdRp6JaKGat8kkIcog "Penetration testing in Application Vulnerability Response enables application owners to assess the security posture of their application. It is the manual testing of an application by the ethical hacking team.").
* A separate API is used to import SBOM data. For more information, see [Exploring Software Bill of Materials](https://www.servicenow.com/docs/_y9uO7ds0dogOuzyG6~gOA "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.") and [Veracode Vulnerability Integration](https://www.servicenow.com/docs/0LsgOYfma41qlFzsb0qEkg "The Vulnerability Response Integration with Veracode application uses data imported from the Veracode product to help you determine the impact and priority of flaws in your code.").

{#app-vuln-mgmt__ul_jkx_wgb_vzb}

CI lookup rules
:   Automatically search application data for matches in the Configuration Management Database (CMDB).

Assignment rules
:   Automatically assign application vulnerabilities based on user groups, user group fields, and scripts.

Risk Calculators
:   Automatically prioritize and rate the impact of AVITs using calculators, based on any criteria, by using condition filters.

Severity mapping
:   Automatically calculate initial values for fields on application vulnerable items. Vulnerability entries have both source severity and normalized severity (based on severity mapping). Severity is tied to the Common
    Weakness Enumeration (CWE).

Remediation target rules
:   Define the expected time frame for remediating an application vulnerable item.

Reporting
:   Quickly gain insight into your security posture, remediation trends and top 10 Applications or Business Units with the most critical AVITs.

The common point for both types of scans is the application release. An application release, which defines a Name string, is the tie-in point to group scanned vulnerability results on the scanner side.
This way AVR knows which application release the results belong to when importing scan results through the integration.

A Configuration Item \[cmdb_ci\] child table, Scanned Applications \[sn_vul_app_scanned_application\], was created in the Vulnerability Response application and scope. This table stores the Application Release abstraction and provides service graphing though its CMDB relationships. They can be viewed from the AllApplication Vulnerability ResponseAdministrationApplications module. The list view for Scanned Applications contains the Department and Support Group added during setup.

## Application Vulnerable Items (AVITs) {#app-vuln-mgmt__section_pvw_hgb_vzb}

For application vulnerabilities, AVR relates a vulnerability to an application to create the application vulnerable item (AVIT) record. Because of the multiple definitions of what constitutes an application in the CMDB, Application Vulnerability Response limits applications to scanned applications. Scanned applications are the applications scanned in your environment identified by AVR as Name and
ID. AVITs are based on the latest scan summary until confirmed Fixed by the scanner. If an AVIT is no longer found, it remains tied to the scan summary where it was last seen.

Application vulnerable items can be viewed from the AllApplication Vulnerability ResponseVulnerabilitiesVulnerable Items module.

If an application is removed from the CMDB, any associated AVITs are closed.

For information on AVIT form fields, see [Application Vulnerable Item fields](https://www.servicenow.com/docs/Kx7R5PkG4Nf4B5Amw4XISA "Application vulnerable items (AVITs) are automatically created during third-part vulnerability integration imports.").

## User groups and roles in Application Vulnerability Response {#app-vuln-mgmt__section_yzs_f52_flb}

Often a team works together to create, manage, and oversee the management of application vulnerabilities. There are strategic roles, as well as operational roles, among the team members. In most organizations, you may
participate in more than one role and often share roles with others. Application Vulnerability Response uses three user groups containing granular roles: App-Sec Manager, Application Security Champion, and Developer. See [Application Vulnerability Response user groups and roles](https://www.servicenow.com/docs/0O_fAfj89m39DVjiQhE_sA#avm-manage-roles "Before you can successfully remediate vulnerabilities with Application Vulnerability Response (AVR), you must assign users to user groups.") for more information on these groups and roles.

## Application Vulnerability Response states

Application Vulnerability Response offers a state model for the status of your application vulnerable items (AVITs) and helps you to determine when and how to remediate your AVITs.

An application vulnerable item has several possible states, see [Application Vulnerable Item (AVI) states](https://www.servicenow.com/docs/3q5xAWNxQUVgHRlvFA~dlQ "Application Vulnerability Response offers a state model for the status of your application vulnerable items (AVIs), at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to remediate your AVIs.") for more information.

## Vulnerability Response applications and CSDM tables {#app-vuln-mgmt__id_pt4_yzh_q2c}

The Vulnerability Response, Application Vulnerability Response, third-party vulnerability integrations and Software Bill of Materials applications manage (contribute data to) CSDM tables. These applications also use data from CSDM tables that other applications generate. Several ServiceNow products, therefore, benefit from and add value to these Security Operations applications. See [Vulnerability Response applications and CSDM tables](https://www.servicenow.com/docs/gMP4dJ0RV~ri54r65307QA "The Vulnerability Response, Application Vulnerability Response, third-party vulnerability integrations and Software Bill of Materials applications manage (contribute data to) CSDM tables. These applications also use data from CSDM tables that other applications generate. Several ServiceNow products, therefore, benefit from and add value to these Security Operations applications.") for more information.

*[\>]: and then


