Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with Application Vulnerability Response

Several types of components are installed with activation of the Application Vulnerability Response feature, including tables, user roles, and scheduled jobs.

Starting with v24.0.6 of Application Vulnerability Response, the most frequently used system properties are now accessible within the Application Vulnerability Response application. To view these system properties, navigate to AllApplication Vulnerability ResponseProperties.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Demo data is available for this feature.

Roles installed

Granular roles in Application Vulnerability Response are assigned to specific User Groups, by default.

Note: Using granular roles outside these user groups requires coding and advanced Application Vulnerability Response or ServiceNow expertise.

Role title \[name\]DescriptionContains roles
V20.0: sn\_vul.app\_manage\_auto\_exception\_ruleCreate, update, delete, and cancel \(deactivate\) exception rules.sn\_vul.app\_read\_auto\_exception\_rule
sn\_vul.app\_manage\_group\_rulesRead, write, delete, and all operations on application remediation task rules.- sn\_vul.app\_read\_all - sn\_vul.app\_read\_group\_rules
V20.0: sn\_vul.app\_exception\_approverApproves exception rules and exception rule extension requests.Starting from v20.0, the granular role, sn\_vul.app\_read\_all, has been removed for this role so that you can access the application vulnerable items and remediation tasks assigned to you and your group instead of all the application vulnerable items and remediation tasks.- sn\_vul.app\_read\_auto\_exception\_rule - sn\_vul.view\_manager\_workspace
sn\_vul.app\_false\_positive\_approverApproves or rejects false positive requests.sn\_vul.view\_manager\_workspace
sn\_vul.app\_read\_assignedView application vulnerable items (AVIs) assigned to you either in both the Classic UI and IT Remediation Workspace.Important: Starting with v24.0 of Vulnerability Response, the sn_vul.app_read_assigned role has the privilege to access the IT Remediation Workspace.sn\_vul.view\_rem\_workspace
sn\_vul.app\_read\_allView all AVIs and related information either in the Classic UI or Vulnerability Manager Workspace.Important: Starting with v24.0 of Vulnerability Response, the sn_vul.app_read_all role has the privilege to access the Vulnerability Manager Workspace.sn\_vul.view\_manager\_workspace
sn\_vul.app\_write\_assignedUpdate AVIs assigned to you. 
sn\_vul.app\_write\_allUpdate all AVIs and related information. 
sn\_vul.app\_update\_assignment\_groupUpdate AVI Assignment group.Note: When used outside of the default user group requires sn_vul.app_write_all or sn_vul.app_write_assigned.
sn\_vul.app\_update\_assigned\_toUpdate AVI assignee.Note: When used outside of the default user group requires sn_vul.app_write_all or sn_vul.app_write_assigned.
sn\_vul.app\_configure\_integrationsConfigure third-party integrations.

sn_vul.app_read_all

sn_vul.app_read_integrations

sn_sec_int.admin

sn_vul_veracode.configure_integration

sn_vul.configure_nvd_administration

Note: To define or edit an App-Sec Manager user group by single or specific integrations, see Vulnerability Response personas and granular roles.

sn\_vul.app\_read\_integrationsView all third-party integrations. 
sn\_vul\_veracode.configure\_integrationDefine, update, and delete Veracode integrations. 
sn\_vul.app\_manage\_assignment\_rulesDefine, update, and delete AVI assignment rules.sn\_vul.app\_read\_all sn\_vul.app\_read\_assignment\_rules
sn\_vul.app\_read\_assignment\_rulesView assignment rules. 
sn\_vul.app\_manage\_remediation\_target\_rulesDefine, update, and delete AVI remediation target rules.sn\_vul.app\_read\_all sn\_vul.app\_read\_remediation\_target\_rules
sn\_vul.app\_manage\_risk\_score\_configurationsDefine, update, and delete AVR calculators and risk rules.sn\_vul.app\_read\_all sn\_vul.app\_read\_risk\_score\_configuration sn\_sec\_cmn.calc.write
sn\_vul.app\_read\_risk\_score\_configurationView AVR calculators and risk rules. 
sn\_vul.app\_manage\_applicationsView, update, and delete application records. 
sn\_vul.app\_manage\_app\_scGives a Security Champion the ability to add or remove themselves from the Scanned Application related list. 
sn\_vul.app\_pa\_sc\_viewProvides relevant view to the specific Security Champion. 
sn\_vul.app\_manage\_app\_vul\_permissions\[internal\] Used by sn\_vul.app\_manage\_applications. 
sn\_vul.app\_manage\_normalized\_severityUpdate mapping to normalized severity.sn\_vul.app\_read\_normalized\_severity
sn\_vul.app\_read\_normalized\_severity \[Removed in v12.1. Don’t use.\]View normalized severity records. 
sn\_vul.app\_read\_application\_releaseView application release records. 
sn\_sec\_int.adminProvides access to integrations. 
pa\_power\_userProvides access to reportspa\_viewer
sn\_vul.app\_sec\_managerPrioritizes and manages application vulnerable items. 
sn\_vul.app\_developerDeveloper responsible for fixing the application vulnerabilities. 
sn\_vul.app\_create\_watch\_topicCreate Watch Topics for application vulnerabilities. 
sn\_vul.app\_read\_watch\_topicRead Watch Topics for application vulnerabilities. 
sn\_vul.app\_edit\_watch\_topicEdit Watch Topics for application vulnerabilities. 
sn\_vul\_blackduck.configure\_integrationConfigure third-party integrations.sn\_vul\_blackduck.configure\_integration

Scheduled jobs installed

For Vulnerability Response shared scheduled jobs see, Components installed with Vulnerability Response.

Scheduled jobDescription
Associate existing AVIs with Auto Exception RuleEvaluates application vulnerable items for matches to exception rules.
Populate Entry and CVE M2MMakes existing records consistent with multiple CWE records. Run once after upgrade to populate then disable.
Resync primary CWEFor customized primary CWE calculations. Run once after upgrade to resync then disable.
Rollup application vulnerable item values to vulnerability and groupCalculates vulnerabilities and group roll ups for application vulnerable items.Note: Starting with v23.0 of Application Vulnerability Response, the scheduled job is enhanced to create background jobs with multithreading capabilities. This upgrade involves segmenting the job into several smaller child jobs, which are executed either in parallel or concurrently. This modification enables processing of multiple records simultaneously, thus significantly speeding up the overall task.
Black Duck Project List IntegrationPulls and ingests data into the Black Duck projects table.
Black Duck Application List IntegrationImports applications into discovered applications table for all the project versions available with Black Duck Integration in projects table.
Black Duck Application Vulnerable Item IntegrationIngests vulnerable items into ServiceNow application based on the vulnerabilities detected by scanners for every discovered application in the system.

Tables installed

TableDescription
Application Release\[sn\_vul\_app\_release\]Contains application version information.
Version 13.0: Application Security Champions \[sn\_vul\_app\_m2m\_app\_sc\]Contains the Application Vulnerability Response Security Champion group records.
Application Vulnerability Entry\[sn\_vul\_app\_vul\_entry\]Contains application vulnerability entries.
Application Vulnerability Integration \[sn\_vul\_app\_integration\]Contains Application Vulnerability Response integration records.
Application Vulnerability Scan Location\[sn\_vul\_app\_vul\_scan\_location\]Contains third-party scan location information.
Application Vulnerability Scan Summary\[sn\_vul\_app\_vul\_scan\_summary\]Contains third-party scan summary information.
Application Vulnerable Item\[sn\_vul\_app\_vulnerable\_item\]Contains AVI records. Starting with v19.0, the following columns are added for Software Bill of Materials: - sn\_sbm\_config\_rule - sn\_sbom\_component - vex\_justification - vex\_detail - vex\_response - vex\_state - sca\_type \(SBOM-SCA\)
Scanned Application\[sn\_vul\_app\_scanned\_application\]Contains application information.
State Map\[sn\_vul\_app\_state\_map\]Contains state mapping from third-party integrations to application vulnerable item \(AVI\) states.
Vulnerability CWEs\[sn\_vul\_m2m\_entry\_cwe\]Links CVE data to application vulnerable entries.
Application Remediation Task Manifestsn\_vul\_app\_rt\_manifestAny updates on remediation task are done by using this manifest table by scheduled jobs.
Application Remediation Task sn\_vul\_app\_vulnerabilityContains application remediation tasks.
Application Remediation Task Itemsn\_vul\_app\_m2m\_vul\_group\_itemM2M table between AVI and application remediation tasks.
Version 21.0:Application Vulnerable Items sn\_vul\_app\_vulnerable\_itemContains AVI records.
Version 21.0: Package \[sn\_vul\_app\_package\]Contains application package details.
Version 21.0:Licenses sn\_vul\_app\_licenseContains application licenses.
Version 21.0:Application Remediation Tasks sn\_vul\_app\_vulnerabilityContains application remediation tasks.
sn\_vul\_blackduck\_configContains Black Duck integration configuration details.
sn\_vul\_blackduck\_projectContains details of the projects coming from Black Duck.
sn\_vul\_blackduck\_project\_importImport set table for the Black Duck project ingestion.
sn\_vul\_blackduck\_app\_importImport set table for the Black Duck application ingestion.
sn\_vul\_blackduck\_avit\_importImport set table for the Black Duck AVIT ingestion.