---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Container Vulnerability Response

# Container Vulnerability Response {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Container Vulnerability Response

The ServiceNow Container Vulnerability Response application helps you import and manage container vulnerable items (CVITs) by integrating vulnerability data from internal and external sources such as the National Vulnerability Database (NVD) and third-party security products.
It enables effective remediation of container vulnerabilities by linking vulnerability data with runtime contextual information like hosts, Kubernetes clusters, services, and namespaces.
Show full answer Show less  
This application also integrates with ServiceNow Kubernetes Discovery to relate vulnerabilities to relevant Kubernetes entities within the Configuration Management Database (CMDB), providing a comprehensive view of container security status.

## Key Features

* **Source Identification:** Links CVITs to Docker images rather than running containers for precise vulnerability tracking.
* **Granularity Configuration:** Allows tracking vulnerabilities at multiple levels including image, Kubernetes cluster, namespace, or service level.
* **Version Tracking:** Monitors new image versions to identify fixed vulnerabilities and automatically resolves older vulnerabilities when updated images are deployed.
* **Image Type Differentiation:** Separately tracks CVITs in base images and application images for targeted remediation strategies.
* **Exception Management:** Supports raising exception requests or false positive requests with multi-level approval workflows and enables defining exception rules to defer CVITs automatically.
* **Integration:** Supports integration with third-party container security tools like Prisma Cloud Compute from Palo Alto Networks.
* **Reporting:** Provides a detailed dashboard with insights into vulnerability trends and remediation progress.

## Benefits

* Centralizes container vulnerability data with runtime context for more informed remediation decisions.
* Improves visibility by connecting vulnerabilities to Kubernetes entities via the CMDB.
* Automates resolution of vulnerabilities linked to outdated container images, reducing manual overhead.
* Facilitates compliance and security processes with exception handling and approval mechanisms.
* Offers actionable analytics through comprehensive reporting dashboards.

## Getting Started

To begin using Container Vulnerability Response, familiarize yourself with Security Operations in your ServiceNow AI Platform instance and explore the Security Operations applications available in the ServiceNow Store. For detailed concepts, configuration guidance, integration options, workspace usage, remediation procedures, and analytics, refer to the Container Vulnerability Response documentation and release notes for the Brazil version.  
The ServiceNow®
Container Vulnerability Response application imports container vulnerable items (CVITs) and according to the rules enables you to remediate
container vulnerabilities. Vulnerability data is pulled from internal and external sources, such as the National Vulnerability Database (NVD) or third-party integrations.

## Request apps on the Store {#cvr-landing__section_vxk_psm_1jb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#cvr-landing__inline-send-to-store}

|-|-|-|
| [Explore Learn about Container Vulnerability Response concepts and features.](https://www.servicenow.com/docs/u_K4mH1YLPcBcCaHrCF~MA "The Container Vulnerability Response application imports container vulnerable items (CVITs). According to the rules, the feature enables you to remediate the container vulnerabilities. Container Vulnerability Response is available through a separate subscription.") | [Configure Configure Container Vulnerability Response.](https://www.servicenow.com/docs/hZQccY2lAi4NN0h65zoBag "Before you run Container Vulnerability Response in your ServiceNow AI Platform instance, you must configure it.") | [Integrate Extend Container Vulnerability Response by integrating with other applications.](https://www.servicenow.com/docs/kusPoEX_MzS7IbDb5UHGXA "Extend the capabilities of Container Vulnerability Response by integrating with other applications.") |
| [Use the Vulnerability Response Workspaces Learn how to monitor, manage and remediate CVITs in the Vulnerability Manager, IT Remediation, and Vulnerability Assessment Workspaces.](https://www.servicenow.com/docs/wiqlj1NKVgLknKi9NlmB2w "Vulnerability Response Workspaces offer a consolidated view of the features that enables you to multi-task from within the same pane by boosting productivity and saving time.") | [Remediate Learn how to remediate container vulnerabilities.](https://www.servicenow.com/docs/Fd5J_suEwNEKoytSq3_rNQ "Monitoring remediation is a process that begins with reviewing status and ends with closing container vulnerable items (CVITs). Container Vulnerability Response offers tools and procedures to make that process more productive and efficient.") | [Analytics \& Reporting View Container Vulnerability Response analytics](https://www.servicenow.com/docs/Bs~aO1NHqc8dUdp0pWjXMA "This Platform Analytics Solution contains prepackaged Platform Analytics content for use with other ServiceNow AI Platform products. This Platform Analytics Solution provides an exposure on how vulnerabilities are managed through the various charts.") |
| [Reference Get details about Container Vulnerability Response components like fields, tables and properties.](https://www.servicenow.com/docs/iQRORQBMzXVLyGkvEAZKwQ "Reference topics containing information about tables, roles, and properties installed with the Container Vulnerability Response.") | [Upgrade Container Vulnerability Response to USEM Upgrade Container Vulnerability Response applications to Unified Security Exposure Management.](https://www.servicenow.com/docs/qYaIyq4z9kNZmFe74FX8wA "The Migration assistant for Unified Security Exposure Management is a centralized utility that guides and automates the migration from Vulnerability Response applications to Unified Security Exposure Management (USEM). USEM provides a unified foundation that consolidates data models, streamlines features, and enhances performance and scalability across all Security Exposure Management applications.") |   |
[Table 1. Container Vulnerability Response]

{#cvr-landing__table_myz_gt3_b5c}

## Benefits {#cvr-landing__id_ntb_vq1_fxb}

The Container Vulnerability Response application provides the following benefits:

* Integrates with third-party container security products, like Prisma Cloud Compute from Palo Alto Networks.
* Imports vulnerability data for the images that are deployed to runtime, and enriches the vulnerability data with runtime contextual information (hosts, Kubernetes clusters, services, and namespaces).
* Provides a list of the references created from vulnerabilities to the relevant Kubernetes entities in the Configuration Management Database (CMDB) using ServiceNow Kubernetes Discovery.
* Offers a comprehensive reporting dashboard, providing insights into the vulnerability and remediation trends.
{#cvr-landing__ul_amv_tbl_5xb}

## Key features {#cvr-landing__section_mzl_kr1_fxb}

The Container Vulnerability Response application manages vulnerabilities detected in the containers. It provides the following features:

* Point to source Docker Image from CVITs instead of running containers.
* Configure granularity of CVITs to track at image, Kubernetes cluster, namespace, or service level.
* Track new image versions to identify fixed vulnerabilities. Any vulnerabilities reported in older versions are automatically resolved in ServiceNow when new image versions are deployed at runtime.
* Track CVITs in Base images separately from Application images to enable independent remediation.
* Raise exception requests or false positive requests, which can be reviewed through a multi-level approver process.
* Define exception rules to defer CVITs automatically.
{#cvr-landing__ul_dmt_xqm_vsb}

## What's new {#cvr-landing__section_ysn_tnb_fxb}

To learn more about what's new and what's changed in Brazil, see the Brazil release notes.

## Get started {#cvr-landing__section_pqm_vfr_qjb}

* For an overview about Security Operations in your ServiceNow AI Platform instance, see [Understanding Security Operations](https://www.servicenow.com/docs/1kjXFTXOeXINWbSppN2d5A#understanding-secops "Protect your assets and enterprise environment with ServiceNow Security Operations applications and the power of the ServiceNow AI Platform. Connect your security and IT teams to help you prioritize and resolve threats based on the impact they pose to your organization.").
* For information about all the Security Operations applications available for download from the ServiceNow Store, see [Security Operations and the ServiceNow Store](https://www.servicenow.com/docs/ZtVWjwQgCFBPJF8J_uu3Aw "Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.").
{#cvr-landing__ul_bpm_1ht_vjb}

