---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# National Vulnerability Database (NVD) integration

# National Vulnerability Database (NVD) integration {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of National Vulnerability Database (NVD) integration

The National Vulnerability Database (NVD) integration leverages data from the NIST NVD to help ServiceNow Vulnerability Response customers assess the impact and prioritize remediation of vulnerabilities in their software.
This integration should be part of the initial setup of Vulnerability Response and run before importing vulnerability data from third-party scanner products.
It enriches vulnerability data by mapping Common Vulnerabilities and Exposures (CVE) and Common Platform Enumeration (CPE) information directly into your instance.
Show full answer Show less  
The NVD integration runs as scheduled jobs, typically daily or weekly, to keep your vulnerability data synchronized and up to date. It is designed to integrate seamlessly with third-party vulnerability scanners such as Qualys by linking their identifiers to NVD CVEs, enabling a comprehensive view of vulnerabilities and their relationships.

## Key Features

* **Automatic Scheduled Jobs:** The primary NVD integration (CVE only) runs daily by default, maintaining current vulnerability data without manual intervention.
* **Multiple Integration Options:** Includes separate integrations for CVE data, CPE data, and unmapped CPE data. Only the CVE integration is active by default; others can be activated as needed to capture additional vulnerability metadata.
* **Data Enrichment:** Incorporates CWE (Common Weakness Enumeration) data and Stakeholder-Specific Vulnerability Categorization (SSVC) decision values, enhancing vulnerability context and prioritization.
* **Third-Party Library Support:** Supports importing and updating third-party vulnerability libraries, linking them to NVD entries for enriched visibility within Vulnerability Response.
* **Run-As User Configuration:** Uses a preconfigured run-as user (VR.System) for integration jobs, which should not be changed to ensure proper operation.

## Practical Usage and Best Practices

* Run the NVD integration (CVE) and CWE imports before importing data from third-party scanners to ensure enriched and accurate vulnerability data.
* Schedule CWE updates before NVD updates; by default, NVD updates run weekly on Mondays.
* Verify successful installation and initial data import of the Vulnerability Response Integration with NVD application before relying on vulnerability data.
* Activate additional integrations for CPE data if your vulnerability management requires formal software naming and system binding details.
* Monitor integration run statuses to ensure data synchronization is functioning as expected.
* Note that activation of this plugin in production may require a separate license.

## Where to Access and Manage

To view and manage NVD integrations, navigate within ServiceNow to **Vulnerability Response** or **Application Vulnerability Response \> Administration \> Integrations**. Here you can:

* View the active NVD integrations.
* Activate or deactivate CPE-related integrations as necessary.
* Manually execute scheduled jobs if needed.

## Key Outcomes

* Enables accurate and enriched vulnerability data within ServiceNow Vulnerability Response, improving prioritization and remediation workflows.
* Maintains synchronization between your instance and authoritative NVD data through automated scheduled imports.
* Facilitates integration with third-party scanner data for a unified vulnerability management experience.
* Provides additional vulnerability context through CWE and SSVC enrichment to support risk-based decision-making.  
The NVD integrations use data from the NIST National Vulnerability Database to help you determine the impact and priority of flaws in your code. Run this
integration as part of your initial setup of Vulnerability Response and before importing vulnerability data into your instance with a third-party scanner product.

## Request apps on the Store {#nvd-vuln-integration__section_wlq_1kz_thb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#nvd-vuln-integration__inline-send-to-store}
The NIST NVD collects both Common Vulnerabilities and Exposures (CVE) and Common Platform Enumeration (CPE) data and makes that data available to the ServiceNow AI Platform®. It easily integrates with Vulnerability Response to map CVE and CPE vulnerabilities enriching the data in your instance.  
Important:  
There's a configured run-as user for each integration record. The default value for this user is VR.System. Don't change this value.  
After it's installed, the NIST National Vulnerability Database Integration-API (CVE only) integration is invoked automatically as a scheduled job and runs daily. You can also execute individual scheduled jobs manually. Scheduled jobs simplify the vulnerability remediation life cycle by keeping the instance synchronized with other vulnerability management systems.  
Tip:  
Activation of this plugin on production instances may require a separate license.  
Note:  
Unified Security Exposure Management (USEM) enriches CVE entries with Stakeholder-Specific Vulnerability Categorization (SSVC) decision values from the NVD, which appear as new fields in the Exploitability section of the CVDB record. See [SSVC enrichment for CVEs](https://www.servicenow.com/docs/arRULRunMtbyZc9sWGG72w "Unified Security Exposure Management (USEM) enriches CVE entries with SSVC (Stakeholder-Specific Vulnerability Categorization) decision values from the National Vulnerability Database (NVD). These values provide additional risk signals that you can use to analyze and prioritize vulnerabilities. This enrichment is available only in USEM.") for details on the new fields.

## Available versions {#nvd-vuln-integration__section_gkd_vpw_zhb}

{#nvd-vuln-integration__table_tqh_wpw_zht__entry__2}

| Release version | Release Notes |
|-|-|
| Vulnerability Response Integration with NVD v1.2 |   |
[ ]

{#nvd-vuln-integration__table_tqh_wpw_zht}

## Initial import of vulnerability data with the NVD and CWE integrations {#nvd-vuln-integration__section_spf_m1d_rvb}

1. Perform an initial import of CWE data with the CWE Comprehensive 2000 Integration.See [Configure and run the scheduled job for updating CWE records](https://www.servicenow.com/docs/pQVqsXPJIEg2JsNOwNOvWw "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product."). You perform CWE updates On Demand from the integration record by default, and, you must configure it.

   Note:  
   Schedule the CWE update to run before the NVD database update. The default day for the NVD update is Weekly on Monday.
2. Verify the Vulnerability Response Integration with NVD application is installed and initial data import is successful. See [Install the Vulnerability Response Integration with the NIST National Vulnerability Database](https://www.servicenow.com/docs/PyuqbRH579Ox2dqzt~iipg#install-nvd "Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.") for more information.
3. Third-party libraries are updated as scheduled jobs. Refer to your integration documentation at [Vulnerability Response integrations](https://www.servicenow.com/docs/mL4s4OXp~T5tbyCNd3o2EQ "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") for more information about third-party integrations.
{#nvd-vuln-integration__ol_dkg_bsj_tvb}

## Imported vulnerability data and vulnerable items {#nvd-vuln-integration__section_dvh_z3d_5vb}

In your ServiceNow AI Platform instance, each imported vulnerability is represented by a vulnerability entry in the source libraries of third-party scanner products like Qualys, for example. The vulnerable items (VI)s that are imported and updated in your instance are references to third-party libraries, such as the Qualys library. A third-party library can, in turn, reference back to the NVD.

For example, when you ingest third-party vulnerability data from a product like Qualys, you're ingesting VIs that reference a QID (Qualys Identifier). In the case of Qualys, that QID in turn references a CVE from the NVD library. When you select that QID in a remediation task or vulnerable item record in the Vulnerability Response application, and you have run the NVD and CWE integrations to ingest data, you're viewing current, enriched vulnerability data that lets you see the relationships that exist between your VIs and CVEs,
CWEs, and CPEs.

Before you run a third-party scanner product like Qualys that has its own library, you must first install and run, at a minimum, the NIST National Vulnerability Database Integration- API (CVE only) integration (also includes CISA-related details), CWE
Integration to ingest vulnerability data. These NVD and CWE data imports enrich your Vulnerability Response or Application Vulnerability Response data before importing data with a third-party product.

For more information about managing the NVD, CWE, and third-party libraries and viewing them, see [Importing data with the NVD and CWE integrations and managing third-party libraries](https://www.servicenow.com/docs/ejCDnLMp8XZiPtSgiquAXQ "If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.") and [View Vulnerability Response vulnerability libraries](https://www.servicenow.com/docs/owDaXqXohD7O47pKarrbvA "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.").

After you verify the successful NVD import, to further enrich your vulnerability data, [Configure and run the scheduled job for updating CWE records](https://www.servicenow.com/docs/pQVqsXPJIEg2JsNOwNOvWw "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.").

Perform the NVD and CWE imports before importing vulnerability data with a third-party product. Third-party libraries are updated as scheduled jobs. Refer to your integration documentation at [Vulnerability Response integrations](https://www.servicenow.com/docs/mL4s4OXp~T5tbyCNd3o2EQ "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") for more information about third-party integrations.

## Locating the NVD integrations {#nvd-vuln-integration__section_ift_yxh_x1b}

To view the NVD integrations, navigate to Vulnerability Response or Application Vulnerability ResponseAdministrationIntegrations.  
The following integrations are included in the base system.  
Note:  
Only the NIST National Vulnerability Database Integration - API (CVE only) integration is active, by default.  
{#nvd-vuln-integration__table_sbn_qlp_dt__entry__2}

| Integration | Description |
|-|-|
| NIST National Vulnerability Database Integration - API (CVE only) | Retrieves only NIST NVD vulnerability data (CVE). By default, this integration is automatically set to run daily. |
| NIST National Vulnerability Database Integration-API (CPE only) | Retrieves CPE data from NIST NVD. This integration is inactive by default. Activate this integration if you want to capture CPE data that includes a formal name format, a method for checking names against a system, and a description format for binding text and tests to a name. This information is stored in Vulnerable Software. This integration is set to run daily and is inactive by default. To activate this integration, see [Activate the NIST National Vulnerability Database--API (CPE only)](https://www.servicenow.com/docs/PyuqbRH579Ox2dqzt~iipg#activate-nist-nvd-cpe-only-integration "To ingest Common Platform Enumeration (CPE) data, you can perform a full data import with a daily scheduled job."). |
| NIST National Vulnerability Database Integration-API (Unmapped CPE) | Retrieves CPE data associated with fetched CVE from NIST NVD. This integration is inactive by default. Activate this integration if you want to capture CPE data that includes a formal name format, a method for checking names against a system, and a description format for binding text and tests to a name. This information is stored in an NVD vulnerability entry record related list. This integration is set to run On Demand and is inactive by default. To activate this integration, see [Activate the NIST National Vulnerability Database--API (Unmapped CPE)](https://www.servicenow.com/docs/PyuqbRH579Ox2dqzt~iipg#activate-nist-nvd-unmapped-cpe "To ingest Common Platform Enumeration (CPE) data for fetched Common Vulnerabilities and Exposures (CVE) data, you can perform a full data import with an on-demand scheduled job."). |
[Table 1. NVD integrations]

{#nvd-vuln-integration__table_sbn_qlp_dt}  
Important:  
The "NIST National Vulnerability Database Integration-API (CVE and CPE)" integration is deprecated.

For integration run statuses see, [View the (National Vulnerability Database) NVD integration import run status](https://www.servicenow.com/docs/n1mCErvd7KA3i1zk1DQk~g "Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.").

*[\>]: and then


