Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Vulnerability Response vulnerability form fields

Vulnerabilities are created automatically when records are downloaded from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-party integrations and stored under Libraries in Vulnerability Response.

NVD entry fields

To view imported data in the fields listed in the following tables, you must have, at a minimum, the sn_vul.read_all role.

These fields are found on records listed in the National Vulnerability Database Entries [sn_vul_nvd_entry] table.

FieldDescription
IDIdentifier for this vulnerability entry.
Risk rating

(Hidden when no VITs are associated with the vulnerability)

Quantified Risk Score separating vulnerable items into Critical, High, Medium, Low, and None. For more information on risk ratings, see Vulnerability Response calculators and vulnerability calculator rules.

Note: This base Risk rating is not the same as the Solution record Risk rating.

Risk score

(Hidden when no VITs are associated with the vulnerability)

Calculated amount of risk the vulnerable item poses to your environment.

Note: This base Risk score is not the same as the Solution record Risk score.

For more information, see Vulnerability Response calculators and vulnerability calculator rules.

SeverityNormalized degree of severity of this vulnerability. Severity maps are provided for NVD and with ServiceNow third-party integrations. For more information on creating or adjusting severity maps, see Create a Vulnerability Response severity map.
Exploit existsYes, if at least one exploit is associated with this vulnerability.
Exploit skill levelLowest skill level required to exploit this vulnerability.
Exploit attack vectorMost vulnerable attack vector of the exploits for this vulnerability. Available when SAM NVD is enabled.
Active VIs

(Hidden when no VITs are associated with the vulnerability)

Number of vulnerable items associated with this vulnerability, not in the Closed state. If there are no active VIs for this vulnerability, Risk Rating and Risk Score are not displayed.

CWE entryReference to the Common Weakness Enumeration element that this vulnerability best fits into.
Date publishedDate the vulnerability was published.
Last modifiedDate the vulnerability was last modified.
SummaryDescription of the vulnerability.
Threat intel \(starting with Vulnerability Response version 20.0\)Threat intelligence provided by Qualys. With this data, you can understand a threat actor's motives, targets and attack behaviors.
Vulnerability Details
CVSS v2Imported CVSS v2 data
CVSS v3Imported CVSS v3 data, not available prior to 2015.
Preferred solution\(Hidden when no VITs are associated with the vulnerability\) Solution of the highest-supersedence in the chain, derived from the solutions referenced in the vulnerability. If more than one highest-supersedence exists in the chain, no value is set. Any value set manually can be overwritten on subsequent imports. Setting this value manually should be done on the vulnerable item.
CISA Exploit (This tab is available only when the CISA application is installed.)
CISA due dateDeadline to resolve the vulnerability.
Date addedDate when the vulnerability was added to the CISA catalog.
ProductProduct on which the vulnerability was identified.
Vendor/ProjectVendor associated with the identified vulnerability.
Known ransomwareStarting from v21.0 of Vulnerability Response.Selected when the field Known To Be Used in Ransomware Campaigns is ingested from the CISA Known Exploited Vulnerabilities (KEVs) catalog. The flag is set at the Common Vulnerabilities and Exposures (CVE) level and rolled up to the third-party entry (TPE).
Remediation Status (Hidden when no VIs are associated with the vulnerability)
Excludes Deferred
Vulnerable itemsNumber of active vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
Total VIsTotal number of vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
%VIs remediatedPercent complete for remediation of vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
Includes Deferred
Vulnerable itemsNumber of active vulnerable items with this vulnerability.
Total VIsTotal number of vulnerable items with this vulnerability.
%VIs remediatedPercent complete for remediation of vulnerable items with this vulnerability.
Related Links
Update statusDisplays date and time of the last update. Updates the following: - Remediation task state - Risk score and rating - Metrics such as Active VITs, Total VITs from the Remediation Status section
Related Lists
Vulnerable Items\(Hidden when no VITs are associated with the vulnerability\) Vulnerable items associated with this vulnerability.
Vulnerability ReferencesInformation about the vulnerability from external sources, cited by NVD.
ExploitsExploits associated with this vulnerability.
Solutions\(Hidden when no VITs are associated with the vulnerability\) All Vulnerability Solution Management integration solutions associated with this vulnerability.
WeaknessesImported Weakness data associated to a Common Vulnerabilities and Exposures (CVE).
Vulnerable Software\(Hidden when software is associated with the CVE\) Imported Common Platform Enumeration \(CPE\) data associated with the vulnerability.
Vulnerability Malware KitsMalware imported from various scanner sources, for a vulnerability.

CWE vulnerability entry fields

These fields are found on records listed in the CWEs [sn_vul_cwe] table.

FieldDescription
CWE-IDIdentifier for this vulnerability entry. This identifier is used for both Categories and Weaknesses, and are unique between the two datasets.
NameDescriptive name assigned to this CWE-ID.
Likelihood of exploitHow likely the weakness is to be exploited, on a qualitative scale. One of:- Unknown - Low - Medium - High
OWASP Top 10 PositionThis vulnerability's numerical position in the OWASP top 10 list.
SANS To 25 PositionThis vulnerability's numerical position in the SAN top 25 list.
ClassType of weakness
StatusOne of:- Incomplete - Draft - Stable - Deprecated - Obsolete - Unstable
AbstractionOne of:- Variant - Class - Base - Compound
UpdatedLast time the record was updated in the instance.
Functional areasList of functional areas affected. For example, File Processing. Only populated for 24/862 weaknesses.
Affected ResourcesList of affected resources. For example, File or Directory. Only populated for 51/863 weaknesses.
URLKnowledge base article associated with this vulnerability.
DescriptionDescription of the vulnerability.
Integration runThe integration run this CWE was imported in.
Sections
Additional detailsSoftware concept descriptions that further explain the weakness. Includes:- Extended description - Background details - Notes
Detection methodsDetails on how you might detect this weakness in an application.
Modes of introductionThe phases in which the weakness is introduced for example, Implementation, Architecture and Design, and so on.
Demonstrative examplesCode examples of the weakness with accompanying descriptions.
Potential mitigationsDetails on how to prevent the weakness, including which phase of the application lifecycle it occurs in, and effectiveness of the mitigation.
Related Lists
RelationshipsCWEs associated to this vulnerability. Lists relationships between this CWE and others. Can include parent/child, follows/precedes, requiredby/requires \(for composite weaknesses\), CanAlsoBe, PeerOf, MemberOf .
Observed ExamplesSome CVEs that are representative of this weakness.
Common ConsequencesConsequences of a successful exploit, in terms of scope and impact. For example: Scope: Confidentiality Impact: Read Application Data
MembershipsCWE memberships with this vulnerability.
Applicable PlatformsPlatforms associated with this vulnerability.
Application Vulnerability EntriesOther application vulnerability entries associated with one.
External ReferencesInformation about the vulnerability from external sources.

Third-party vulnerability entry fields

These fields are found on records listed in the Third-party Vulnerability Entries [sn_vul_third_party_entry] table.

FieldDescription
IDIdentifier for this vulnerability entry.
Version 16.0: CVEsMultiple Common Vulnerability and Exposures \(CVEs\) associated with this third-party vulnerability.
SourceOrigin of the vulnerability — whether a scanner or physical test.
Risk ratingQuantified Risk Score separating vulnerable items into Critical, High, Medium, Low and None. For more information on risk ratings see, Vulnerability Response calculators and vulnerability calculator rules.Note: This base Risk rating is not the same as the Solution record Risk rating
Risk score

Calculated amount of risk the vulnerable item poses to your environment, based on risk score.

Note: This base Risk score is not the same as the Solution record Risk score.

For more information, see Vulnerability Response calculators and vulnerability calculator rules.

SeverityNormalized degree of severity of this vulnerability. Severity maps are provided for NVD and with ServiceNow third-party integrations. For more information on creating or adjusting severity maps, see Create a Vulnerability Response severity map.
Exploit existsYes, if at least one exploit is associated with this vulnerability.
Exploit skill levelLowest skill level required to exploit this vulnerability.
Exploit attack vectorMost vulnerable attack vector of the exploits for this vulnerability.
Active VIsNumber of vulnerable items associated with this vulnerability, not in the Closed state.
CategoryClassification provided by the third-party integration. Aids in assignment.
Remediation typeTypes of remediation actions. - Patch - Configuration change - Patch and Configuration change - Countermeasure
CWE entryReference to the Common Weakness Enumeration element that this vulnerability best fits into.
PCIWhen the checkbox is selected, the vulnerability is flagged for significant risk for exposure of payment information.
PCI severityLevel of risk for exposure of payment information. \[Qualys only.\]
Date publishedDate the vulnerability was published.
Last modifiedDate the vulnerability was last modified.
SummaryDescription of the vulnerability.
Vulnerability Details
CVSS v2Imported CVSS v2 data
CVSS v3Imported CVSS v3 data, not available prior to 2015.
ThreatDescription of the threat from this vulnerability.
Preferred SolutionSolution of the highest-supersedence in the chain, derived from the solutions referenced in the vulnerability. If more than one highest-supersedence exists in the chain, no value is set. Any value set manually can be overwritten on subsequent imports. Setting this value manually should be done on the vulnerable item.
Remediation notesDescription of the remediation solution pulled from the vendor.
Remediation Status
Excludes Deferred
Vulnerable itemsNumber of active vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
Total VIsTotal number of vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
%VIs remediatedPercent complete for remediation of vulnerable items with this vulnerability. This count excludes deferred vulnerable items.
Includes Deferred
Vulnerable itemsNumber of active vulnerable items with this vulnerability.
Total VIsTotal number of vulnerable items with this vulnerability.
%VIs remediatedPercent complete for remediation of vulnerable items with this vulnerability.
Related Links
Update statusDisplays date and time of the last update. Updates the following: - Remediation task state - Risk score and rating - Metrics such as Active VIs, Total VIs from the Remediation Status section
Related Lists
Vulnerable ItemsVulnerable items associated with this vulnerability.
Vulnerability ReferencesInformation about the vulnerability from external sources, cited by NVD.
CVEsCommon Vulnerability Enumeration \(CVE\) record associated with this vulnerability.
CategoriesCategories associated with this vulnerability.
ExploitsExploits associated with this vulnerability.
Vulnerability Malware KitsMalware kits associated with this vulnerability.
Solutions \(Rapid7\)Solution information from the Rapid7 solution integrations. Displayed when available.
Exploit FrameworksExploit frameworks associated with this vulnerability.
SolutionsVulnerability Solution Management solutions associated with this vulnerability.
CISA Exploit
CISA existsCISA exploit exists for the Third-Party Vulnerabilities Entry table.
CISA due dateDeadline to resolve the vulnerability.