Viewing patch data for the Vulnerability Response patch orchestration integration with HCL BigFix

  • Release version: Zurich
  • Updated September 5, 2025
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Viewing patch data for the Vulnerability Response patch orchestration integration with HCL BigFix

    This integration enables ServiceNow customers to view and manage patch data, patch rollups, vulnerability information, and remediation status directly within their Vulnerability Response (VR) instance. It supports patch orchestration with HCL BigFix, providing comprehensive visibility and control over vulnerabilities and their corresponding patches across the IT environment.

    Show full answer Show less

    Access and Roles

    • To configure and schedule patches, users need the snvulpatchorch.configurepatch role.
    • To view patch information in read-only mode, the snvulpatchorch.readpatch role is required; this role is inherited by snvul.remediationowner and snvuln.vulnerabilityanalyst roles used in IT Remediation and Vulnerability Manager Workspaces.

    Where to View Patch Data

    • IT Remediation Workspace:
      • Home view: access scorecards for Preferred Solutions, Vulnerable Configuration Items (CIs), and Preferred Patches on Vulnerable Items (VIs).
      • List view: see all Patch Update (VPU) records and assigned vulnerable items with available patches.
      • Patch scheduling is possible from VPU, Remediation Task (RT), and Discovered Item (SDI) records.
    • Vulnerability Manager Workspace:
      • Home view on watch topics: view preferred and potential patches, scheduled patch dates, and download status on the Vulnerable Items tab.
      • List view on remediation efforts: patch data is visible on VI records.
    • Classic Environment: Navigate to All > Vulnerability Response > Patches to access Patch Update records.

    Patch Update Records and Data Details

    Patch Update (VPU) records include:

    • Vulnerability solution data from patch vendors via the Vulnerability Solution Management application.
    • Source Remediation Status detailing total vulnerable devices fixable by patches and those missing updates.
    • Remediation Status showing the percentage of VIs remediated and total VIs with preferred patches.
    • Related links to Associated Devices, Vulnerable Items, Patch Deployments, and Patch Requests.
    • Patch Requests submitted by remediation owners for approval.

    All these details are accessible within the VR Workspaces on dedicated tabs.

    State Rollup and Counting Active Vulnerable Items

    The system uses a scheduled job to roll up changes in active Vulnerable Item (VI) counts to key records such as VIT, RT, Vulnerability Solution, and Patch Update. This selective rollup prevents unnecessary data overload by focusing on active vulnerabilities and their patches.

    Viewing Patches Without Solutions

    Customers can view patches that are not linked to vulnerability solutions, facilitating a broader understanding of patch status and coverage.

    Performance Analytics Dashboards Integration

    • Vulnerability Management (PA) Dashboard: Accessible via All > Vulnerability Response > Overview, with patch scheduling status, target dates, and weekly patch counts shown on the Remediation tab.
    • CISO Dashboard: Found at All > Vulnerability Response > CISO Dashboard, displaying patch coverage by criticality, scheduling status, and missed target dates in the Overview tab.

    Note that the remediation tab appears only if patch orchestration integration is installed; otherwise, it remains unpopulated even if Performance Analytics is subscribed.

    Practical Benefits for ServiceNow Customers

    • Centralized visibility into patch and vulnerability data within the ServiceNow platform.
    • Ability to monitor patch deployment status and remediation progress efficiently.
    • Enhanced control over patch scheduling directly from vulnerability and remediation records.
    • Improved reporting and analytics through integrated dashboards for informed decision-making on vulnerability management.

    Patch data and patch rollup data, as well as vulnerability information and remediation status of your vulnerabilities, are displayed on records in your instance.

    Viewing patch data in the Vulnerability Response Workspaces

    Roles required:
    • sn_vul_patch_orch.configure_patch role to configure and schedule patches
    • sn_vul_patch_orch.read_patch to view (read only) patch information on records. This role is inherited with the sn_vul.remediation_owner and sn_vuln.vulnerability_analyst roles that are required for the IT Remediation and Vulnerability Manager Workspaces

    In the IT Remediation Workspace, you can view patches:

    • On the Home view, where you can click scorecards to view records for Preferred solutions on VIs, Vulnerable CIs, and Preferred Patches on VIs.
    • On the List view, where you can view all Patch Update records (VPUs) from the Patches links, and the vulnerable items (VITs) that are assigned to you that have patches.

    You can schedule patches from the following records:

    • From Patch Update (VPU)
    • Remediation task (RT)
    • Discovered Item (SDI) records

    In the Vulnerability Manager Workspace, you can view patches:

    • From the Home view on watch topics, where you can view preferred and potential patches, Patch scheduled dates, and, if the patch has been downloaded all on the Vulnerable Items tab.
    • From the List view on remediation efforts, where you can view patch data on VI records from theVulnerable Items tab.

    From the classic environment view, navigate to All > Vulnerability Response > Patches.

    Patch Update records in the VR Workspaces and in the classic environment view

    Patch data and patch rollup data and status are displayed on records in your instance. Patch records are included as part of the patch orchestration feature of this integration with Vulnerability Response. View Patch (VPU) records in Vulnerability Response Workspaces from the List view in the IT Remediation Workspace. Patch Update records in both the classic view and Vulnerability Response Workspaces includes the following data:

    • Vulnerability solution data and information from patch vendors imported by the Vulnerability Solution Management application.
    • Source Remediation Status that includes the total number of devices that have the a given vulnerability that can be fixed by a patch and any devices that are missing updates.
    • Remediation Status that includes % of VIs remediated and the total VIs that have a patch as a preferred patch.
    • Associated Devices, Vulnerable Items, Patch Deployments and Patch Requests on the Related Links on records in the class view. This data is displayed on tabs on records in the Vulnerability Response Workspaces.
    • Patch Requests that remediation owners have submitted for approval.

    State rollup on vulnerable item records

    For more information about state rollup to records, see Patch data and state rollup for patch orchestration in Vulnerability Response.

    Records that roll up active VI counts

    To avoid rolling up all the patches to all the vulnerabilities, the scheduled job only picks up changes to the active VI count. These count changes and related data are rolled up to the following records in Vulnerability Response:
    • VIT
    • RT
    • Vulnerability solution
    • Patch Update

    Viewing data for patches without solutions

    For more information about viewing patches without solutions, see View patches without solutions in Vulnerability Response.

    Patch data with Vulnerability Response

    The Vulnerability Management (PA) and CISO dashboards are included with a subscription with the Performance Analytics for the Vulnerability Response application. If you have a subscription for Performance Analytics, but do not have a patch orchestration integration installed, the remediation tab is displayed on the CISO dashboard, but it is not populated with data.

    For the Vulnerability Management (PA) dashboard, navigate to All > Vulnerability Response > Overview. Click the Remediation tab and scroll to the bottom of the page to view Patch Updates data: patches scheduled and not scheduled, patches missing their target dates, and weekly counts.

    For the CISO Dashboard, navigate to All > Vulnerability Response > CISO Dashboard. With the Overview tab selected, scroll to the bottom of the page to view Patch Coverage data: Criticality, patches scheduled and not scheduled, and patches missing their target dates.

    For more information about the Vulnerability Response dashboards, see Using the default Vulnerability Response dashboards, Patch orchestration with the Vulnerability Response Workspaces, and Viewing patch orchestration data on the Vulnerability Response dashboards.