Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Vulnerability Response vulnerable item form fields

Vulnerable items are automatically created during third-party vulnerability integration imports.

Vulnerable item fields

To view imported data in the fields listed in the following tables, you must have, at a minimum, the sn_vul.read_all role.

These fields are found on records listed in the Vulnerable Items [sn_vul_vulnerable_item] table.

If you have enabled SAM NVD vulnerability scanning, the records are compared to the software in your Configuration Management Database (CMDB) and matches are found with vulnerable software or configuration items (CIs).

FieldDescription
Select security tagSecurity tag to add metadata to the record or identify who should have access to this security incident record. This field appears only after the vulnerable item has been saved.
NumberAutomatically generated vulnerable item number for this record.
SourceScanner that found this vulnerable item.Starting with v26.1.4 of Vulnerability Response, the Source field is read-only and can't be edited.
Risk ratingQuantified Risk Score separating vulnerable items into Critical, High, Medium, Low, and None. For more information on risk ratings, see Vulnerability Response calculators and vulnerability calculator rules.Note: This base Risk rating isn’t the same as the Solution record Risk rating.
Risk score

Calculated amount of risk the vulnerable item poses to your environment.

Note: This base Risk score isn’t the same as the Solution record Risk score.

For more information, see Vulnerability Response calculators and vulnerability calculator rules.

VulnerabilityID of the vulnerability associated with this vulnerable item.
Configuration itemAffected asset.
StateThis field defaults to Open, but you can change it to Under Investigation if the vulnerability is ready for immediate remediation.
Until date for risk reductionDate on which compensatory controls applied to the vulnerable item expire.Note: This field appears only when the Original risk score value is available.
Assignment groupGroup selected to work on this remediation task.
Assigned toIndividual from the selected assignment group that works on this vulnerability.
CreatedDate this vulnerable item was created in your instance.
Last openedDate the vulnerable item was most recently opened in your instance. Initially, this is the same as the creation date of the vulnerable item, however, if it was closed, then reopened the Last opened date contains the date and time reopened.
UpdatedDate of the last scan.
AgeDuration for which the VI has been active since the date it was last opened. If the VI is closed, the value of the Age field is set to zero.For more information on the Age field, see Vulnerable item age calculation and display. For more information on how to customize the calculation of Age duration, see the KB1703270 article.
Vulnerability
SummaryDescription of the vulnerability.
SeverityNormalized degree of severity of this vulnerability. Severity maps are provided for NVD and with ServiceNow third-party integrations. For more information on creating or adjusting severity maps, see Create a Vulnerability Response severity map.
Vulnerability score \(v3\)CVSS v3 score.
Vulnerability score \(v2\)CVSS v2 score.
Exploit existsYes, if at least one exploit is associated with the vulnerabilities associated with this vulnerable item.
Exploit attack vectorMost vulnerable attack vector of the exploits for the vulnerabilities associated with this vulnerable item.
Exploit skill levelLowest skill level required to exploit the vulnerabilities associated with this vulnerable item.
Date publishedDate the vulnerability was published.
Last modifiedDate the vulnerability was last modified.
ThreatRelevant information about the threat. Pulled from the vulnerable entry record.Note: Any changes made here update the vulnerable entry record.
Remediation notesRelevant solution to the threat, pulled from the vulnerable entry record.
Remediation Available only with Vulnerability Solution Management.
Preferred solutionPreferred solution imported from the vulnerability record. Note: Any manual changes made here don’t change the vulnerability record and remain unchanged on the VI upon subsequent imports.
SummaryImported Summary from the solution record.
Solution typePotential or Preferred solution.
Initial Detection
DNS nameName of the Domain Name Service name. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
NetBIOS nameName of the NetBIOS. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
IP AddressIPv4 or IPv6 address. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
PortAddress of the port
ProtocolName of the protocol.
SSLWhether SSL encryption is used or not.
Detections
StatusState of the detection.
First foundDate the third-party source first found the detection on this asset.
Last foundDate the third-party source last found the detection on this asset.
DNS nameName of the Domain Name Service name. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
NetBIOS nameName of the NetBIOS. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
IP AddressIPv4 or IPv6 address. If a CI isn’t provided, this field is used to look up a matching CI, if one exists.
PortAddress of the port
ProtocolName of the protocol.
SSLWhether SSL encryption is used or not.
Times foundNumber of times this vulnerability has been detected on this asset by the third-party source.
Integration runIntegration run that imported the detection.
Close Available once the vulnerable item has been remediated and closed. Items in this section are read-only.
Closed byWho closed the vulnerable item.
ClosedDate the vulnerable item was closed.
Close notesInformation included in the closure.
Age closedTime period after which the VI was closed. If the VI is reopened, the value of the Age closed field is set to zero.For more information on how the Age closed field, see Vulnerable item age calculation and display. For more information on how to customize the calculation of Age closed duration, see the KB1703270 article.
Notes
Additional comments/Work notesAny relevant information. Select the check box to add Additional comments.Starting with Vulnerability Response v20.0, you can add work notes in the Notes section for a deferred vulnerable item.
ActivityOnly appears when a work note has been created.
Related Links
Calculate Risk ScoreWhen either the Vulnerability Severity or Risk Score calculators is enabled, the Risk Score field is updated.

The following are the vulnerable items related lists.

Related ListDescription
Remediation TasksTasks associated with this vulnerable item.
Affecting TasksTasks associated with this vulnerable item.
Associated IP AddressesAvailable if the Qualys Vulnerability Integration Vulnerability Integration application is installed.IP addresses that are found during de-duplication.
Impacted ServicesBusiness services impacted by this vulnerable item. Shown when this information is available in the `cmdb` record. This information can be entered manually or using the ServiceNow® Service Mapping application. See Service Mapping for more information. If an affected CI associated with the vulnerable item is added or updated, information in this related list is automatically updated when the record is saved.
State Change ApprovalsStatus of change requests and other approval information associated with the VIT.
Qualys TicketsQualys ticket integration information associated with this vulnerable item.