Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Preparing the Common Vulnerability Reporting Framework (CVRF) solution integration

Use the Setup Assistant to prepare for implementing a solution intelligence integration for all the vendors that support the Common Vulnerability Reporting Framework (CVRF) data format.

Before you begin

To integrate with the vendors that provide the solutions, ensure you perform the tasks in the following checklist. You can print the checklist and verify the items listed are completed before you install the application.

TaskDescription
Image omitted: checkbox.png
Checkbox image.
Verify that the following applications are installed from the ServiceNow Store:- Vulnerability Solution Management: For more information about installing Vulnerability Solution Management, see Install Vulnerability Response third-party applications using Setup Assistant and Install the Solution Management for Vulnerability Response application. - Vulnerability Response: For more information about installing and activating the Vulnerability Response application, see Install Vulnerability Response. This integration requires version 16.1 of Vulnerability Response or later.
Image omitted: checkbox.png
Checkbox image.
Verify you have any third-party account credentials available. They are required to edit some solution integrations.
Image omitted: checkbox.png
Checkbox image.
Verify that you have authenticated the vendors for import of solutions using the APIs. For more information on how to authenticate vendors, see Configure Connection and Credential aliases. If you do not want to configure an API-based vendor, you can skip this step.
Image omitted: checkbox.png
Checkbox image.

If you want to configure an API-based vendor other than Cisco, then you must customize the flow and flow action for extracting a unique key and CVRF URL from the response of an advisory. Note: Publishing CVRF URL is not standard across vendors.

To customize the flow for vendors other than Cisco, see Configure a Common Vulnerability Reporting Framework vendor other than Cisco.

You can skip this step if they do not want to configure vendors other than Cisco. By default, the flow for Cisco has been shipped with the application.

Image omitted: checkbox.png
Checkbox image.
Verify that you have an admin group or user who can manage the integration. If not assigned, the admin assigns the vulnerability admin \(sn\_vul.vulnerability\_admin\) and other roles.