---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Fortify Vulnerability Integration

# Fortify Vulnerability Integration {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Fortify Vulnerability Integration

The Fortify Vulnerability Integration enables ServiceNow customers to import and utilize vulnerability data from the Fortify product within the ServiceNow AI Platform® and the Application Vulnerability Response feature of Vulnerability Response.
This integration helps you assess the impact and prioritize flaws in your code by enriching your instance with third-party vulnerability data collected by Fortify scanners.
Show full answer Show less  
The integration operates automatically through scheduled jobs that run daily and keep your vulnerability data synchronized with Fortify, simplifying the vulnerability remediation lifecycle. A dedicated run-as user (default: **VR.System**) is configured for each integration record and should not be changed.

## Key Features

* **Automated Scheduled Jobs:** Integrations run daily in a chained sequence, with the option to execute individual jobs manually for flexible management.
* **Multiple Integration Components:** The base system includes several integrations that may be activated as needed:
  * **Fortify on Demand Application List Integration:** Retrieves vulnerabilities and metadata from Fortify scanner data to enrich third-party application information. This integration is active by default and runs daily at midnight.
  * **Fortify on Demand Scan Summary Integration:** Obtains scan records from Fortify and runs after the Application List integration. It is inactive by default.
  * **Fortify on Demand Application Vulnerable Item Integration:** Imports scan results, inserts Application Vulnerable Item Tickets (AVITs), and updates vulnerability data. Closed scanner records do not generate new AVITs but update existing ones. Runs after the Scan Summary integration and is inactive by default.
* **Integration Monitoring:** Starting with version 2.3, you can view detailed processing times and reports for the Application Vulnerable Item integration to monitor import performance and status effectively.

## Key Outcomes

* Enhanced vulnerability prioritization and impact assessment by integrating Fortify scanner data directly into ServiceNow.
* Streamlined vulnerability management with automated synchronization between ServiceNow and Fortify vulnerability data.
* Improved visibility into vulnerability scan results and remediation progress through integration run status and vulnerability libraries within ServiceNow.  
The Fortify Vulnerability Integration uses data imported from the Fortify product to help you determine the impact and priority of flaws in your
code.

## Fortify Vulnerability Integration {#fortify-vuln-integration__section_l13_1kz_thb}

The Fortify product collects scanner data and makes that data available to
the ServiceNow AI Platform®. It easily integrates with the ServiceNow®
Application Vulnerability Response feature of Vulnerability Response to map
third-party vulnerabilities enriching the data in your instance.

There is a configured run-as user for each integration record. The default value for this
user is VR.System. Do not change this value.

Every day, scheduled jobs invoke the integrations automatically. Once all the integrations
are activated, they are chained to run in sequence. You can also execute individual
scheduled jobs manually. Scheduled jobs simplify the vulnerability remediation life cycle by
keeping the instance synchronized with other vulnerability management systems.

## Available versions {#fortify-vuln-integration__section_gkd_vpw_zhb}

{#fortify-vuln-integration__table_tqh_wpw_zht__entry__2}

| Release version | Release Notes |
|-|-|
| Vulnerability Response integration with Fortify v2.4 Fortify v2.3 Fortify v2.2 Fortify v2.1 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498) |
[ ]

{#fortify-vuln-integration__table_tqh_wpw_zht}

## Fortify Vulnerability Integration {#fortify-vuln-integration__section_ift_yxh_x1b}

To view the Fortify Vulnerability Integration, navigate to Fortify Vulnerability IntegrationIntegrations.

The following integrations are included in the base system. These integrations are not all
active by default.

After the initial run, every day, scheduled jobs are chained to run the integrations
automatically in order. You can also execute individual scheduled jobs manually. Scheduled
jobs simplify the vulnerability remediation life cycle by keeping the instance synchronized
with other vulnerability management systems.  
{#fortify-vuln-integration__table_sbn_qlp_dt__entry__2}

| Integration | Description |
|-|-|
| Fortify on Demand Application List Integration | Retrieves Fortify application scanner data (vulnerabilities, metadata) and enriches your third-party application data. This integration is set to run daily at 00:00:00. It is active by default. |
| Fortify on Demand Scan Summary Integration | Retrieves scan records from Fortify. This integration is chained to run following the Fortify on Demand Application List Integration when activated. It is inactive, by default. |
| Fortify on Demand Application Vulnerable Item Integration | Retrieves scan results from Fortify, inserts AVITs, and enriches your third-party vulnerability data. If the scanner record is in the Closed state, AVITs are not created. Existing AVITs are still updated. Starting with v2.3, view details such as total processing times, average times for pre- and post-integration run processes, and reports on the integration run records for the Application Vulnerable Item integration. This integration is chained to run following the Fortify on Demand Scan Summary Integration when activated. It is inactive, by default. |
[Table 1. Fortify Vulnerability Integrations]

{#fortify-vuln-integration__table_sbn_qlp_dt}

For integration run statuses see, [View the Fortify Vulnerability Integration import run status](https://www.servicenow.com/docs/hM7dneryozaPDCzEf5j6Sw "Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.").

To view data in third-party vulnerabilities, see [View vulnerability libraries](https://www.servicenow.com/docs/iyw9T~9TxM9RL3eW1Mkj0Q "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.").

*[\>]: and then


