Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Security Operations
Table of Contents
Choose your release version
    Home Paris Security Incident Management Security Operations Vulnerability Response Installation of Vulnerability Response and supported applications Additional Vulnerability Response setup tasks Managing NVD, CWE, and third-party data libraries

    Managing NVD, CWE, and third-party data libraries

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    Managing NVD, CWE, and third-party data libraries

    Vulnerability data can be imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties and used to decide whether to escalate a vulnerability group. Once imported, you can update NVD records on-demand or configure a scheduled job to update them or CWE regularly. Vulnerability Response stores them under Libraries.

    The Common Vulnerability Scoring System (CVSS), included in NVD and third-party entries, captures the main characteristics of a vulnerability.Vulnerability Response uses CVSS data to produce a normalized value reflecting vulnerability severity. When the severity is computed, the vulnerability provides a better understanding of the risk posed by this vulnerability to your organization. Severity helps you assess and prioritize vulnerability remediation.

    If this is your first installation of Vulnerability Response, perform an initial import of CWE, and then NVD records when you configure your scheduled jobs. See Configure the scheduled job for updating CWE records and prior to Vulnerability Response v13.0, Configure the scheduled job for updating NVD records (Prior to v13.0) for more information.

    By default, prior to v13.0, all data feeds for NVD Auto-update are disabled. To enable the feeds you want, see Configure the scheduled job for updating NVD records (Prior to v13.0).

    Starting with v13.0, the NIST National Vulnerability Database Integration - API (CVE only) integration is pre-configured and activated. It runs daily. See or Understanding the NVD integrations for more information.

    CWE updates are On Demand, by default, and must be enabled for a scheduled job. See Configure the scheduled job for updating CWE records.

    The Vulnerable items in your system are grouped and are usually managed in bulk, but can be managed individually. Each vulnerability is represented by a vulnerability entry in the library, from the NVD, or a third-party source. For information on the vulnerability entry fields, see Vulnerability Response vulnerability form fields.

    The following libraries are available:
    Libraries Description
    NVD List of vulnerabilities found by NVD and includes security checklists, security-related software flaws, misconfigurations, product names, and impact metrics including exploits.
    CWE

    List of community-developed software weakness types.

    Each CWE record also includes an associated knowledge article that describes the weakness. You cannot escalate a vulnerability from the Common Weakness Enumerations screen, it is for reference only.

    Third-party List of imported third-party vulnerabilities in your instance. Contains a list of related references, vulnerable items, exploits, and CVEs.
    Vulnerable Software Deprecated: List of all vulnerable software in your instance.
    Related tasks
    • View Vulnerability Response vulnerability libraries

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      Managing NVD, CWE, and third-party data libraries

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      Managing NVD, CWE, and third-party data libraries

      Vulnerability data can be imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties and used to decide whether to escalate a vulnerability group. Once imported, you can update NVD records on-demand or configure a scheduled job to update them or CWE regularly. Vulnerability Response stores them under Libraries.

      The Common Vulnerability Scoring System (CVSS), included in NVD and third-party entries, captures the main characteristics of a vulnerability.Vulnerability Response uses CVSS data to produce a normalized value reflecting vulnerability severity. When the severity is computed, the vulnerability provides a better understanding of the risk posed by this vulnerability to your organization. Severity helps you assess and prioritize vulnerability remediation.

      If this is your first installation of Vulnerability Response, perform an initial import of CWE, and then NVD records when you configure your scheduled jobs. See Configure the scheduled job for updating CWE records and prior to Vulnerability Response v13.0, Configure the scheduled job for updating NVD records (Prior to v13.0) for more information.

      By default, prior to v13.0, all data feeds for NVD Auto-update are disabled. To enable the feeds you want, see Configure the scheduled job for updating NVD records (Prior to v13.0).

      Starting with v13.0, the NIST National Vulnerability Database Integration - API (CVE only) integration is pre-configured and activated. It runs daily. See or Understanding the NVD integrations for more information.

      CWE updates are On Demand, by default, and must be enabled for a scheduled job. See Configure the scheduled job for updating CWE records.

      The Vulnerable items in your system are grouped and are usually managed in bulk, but can be managed individually. Each vulnerability is represented by a vulnerability entry in the library, from the NVD, or a third-party source. For information on the vulnerability entry fields, see Vulnerability Response vulnerability form fields.

      The following libraries are available:
      Libraries Description
      NVD List of vulnerabilities found by NVD and includes security checklists, security-related software flaws, misconfigurations, product names, and impact metrics including exploits.
      CWE

      List of community-developed software weakness types.

      Each CWE record also includes an associated knowledge article that describes the weakness. You cannot escalate a vulnerability from the Common Weakness Enumerations screen, it is for reference only.

      Third-party List of imported third-party vulnerabilities in your instance. Contains a list of related references, vulnerable items, exploits, and CVEs.
      Vulnerable Software Deprecated: List of all vulnerable software in your instance.
      Related tasks
      • View Vulnerability Response vulnerability libraries

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login