---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Remediating Application Vulnerability Response vulnerabilities

# Remediating Application Vulnerability Response vulnerabilities {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Monitoring remediation is a process that begins with reviewing status and ends with closing application vulnerable items (AVITs). Application Vulnerability Response offers tools and procedures to make that process more productive and efficient.

## Application Vulnerability Response remediation process {#avm-monitor-rem-prog__section_jk2_s4q_2db}

Application vulnerable item remediation is done manually.  
An overview of the process:

* Log in to your Application Vulnerability Response instance.
* Validate that your rules (CI Lookup, Assignment) for application vulnerable items are working as expected. For information on revising CI Lookup Rules, see [Identify applications in Application Vulnerability Response automatically](https://servicenow-prod.fluidtopics.net/VH8l5LPt7wmwUvrmk3jwCQ "When data is imported from a third-party integration, Application Vulnerability Response automatically uses application data to search for matches in the Configuration Management Database (CMDB). It does this using CI Lookup Rules. These rules identify applications for the application vulnerable item (AVI) record to aid in remediation."). For information on Assignment rules, see [Assign application vulnerable items in Application Vulnerability Response automatically](https://servicenow-prod.fluidtopics.net/LKdr6Hqc4HoiQKL7sojRTA "Automatically assign application vulnerabilities based on application tags, or any of the assignment groups in the Configuration Item [cmdb_ci] or platform assignment groups, to reduce the mean time to assignment.").
* Validate that your remediation targets are correct. See [Automate remediation target tracking in Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/qOaYqnZlVRbfywXMjQKTbw "Application Remediation Target Rules define the expected timeframe for remediating application vulnerable items (AVIs), providing a timeframe for remediating the vulnerability itself. For example, if an application vulnerable item contains a critical risk rating then the vulnerability on that item needs to be fixed within 15 days.") for information on how remediation target rules work and how to revise them. [View the remediation target status of an application vulnerable item](https://servicenow-prod.fluidtopics.net/VwgLha32DtMzlGoQFq6zZQ "When an application vulnerable item (AVI) has nearly reached (or passed) its remediation target date, as defined by a remediation target rule, the AVI record is updated with a status. This information can help you proactively monitor upcoming remediation activities.").  
  Nota:  
  Remediation target rules belong to AVITs. These rules are run when the AVIT is imported.
* Review the dashboards or reports. For example, view dashboards that show AVITs aging by states.  
  Nota:  
  When the Performance Analytics for Vulnerability Response application (com.snc.vulnerability.analytics) is activated, users with certain roles can view data of interest to the members of the App-Sec Manager and Security Champion groups.

  For App-Sec Managers, Performance Analytics for Vulnerability Response contains the Application Vulnerability Response Overview, which can help you monitor areas of concern. See [Analytics and Reporting Solutions for Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/ckmxJaUnvJgRtT5AFMoedQ "Platform Analytics Solutions contain prepackaged Platform Analytics content for use with other ServiceNow AI Platform products. This Platform Analytics Solution presents important metrics for analyzing your Application Vulnerability Management process.") and [Application Vulnerability Management \[PA\] dashboard](TyA196vf2oM3gGDp~OFuZA "Track the volume, performance and progress of application vulnerabilities from initial analysis and detection to containment or remediation.").

  Starting with version 13.0 of the Vulnerability Response application: For Security Champions, Performance Analytics for Vulnerability Response contains the My Application Vulnerabilities dashboard, which can help you monitor your areas of concern. See [My Application Vulnerabilities dashboard](https://servicenow-prod.fluidtopics.net/XgwxUgXFCosDaWStPJYKZA "This dashboard presents important metrics for analyzing your Application Vulnerability Management process, such as viewing remediation target attainment rates.").

  Starting with version 13.0 of the Vulnerability Response application: To limit the amount of data gathered for reports or related lists, see [Define service classifications for Vulnerability Response reporting and related lists](https://servicenow-prod.fluidtopics.net/bCETWMgewc2L83gVpO1KOQ "Bring more focus to reporting and related lists in Vulnerability Response by defining service classifications. In addition, reducing the number of requested service classifications can improve the performance of Vulnerability Response data gathering.").
* Review the state of AVITs, in order of priority, searching for what has changed.
* Revise the risk for the AVITs, as needed. See [Create an application vulnerability calculator](https://servicenow-prod.fluidtopics.net/BJn7xvgDnrnIZSXsr8IG5w "An application vulnerability calculator is a pre-defined formula to calculate a target field when certain criteria are met. Calculators, which calculate the application vulnerable item (AVI) Risk Score, can contain Risk Rules. Risk calculations offer insight in prioritizing remediation.") for more information.
* Reassign the AVIT to an assignment group for remediation, if needed.
* Rescans are triggered automatically by the third-party import schedule.
* After rescan, if the state is Fixed, AVITs are automatically closed during import.
* After the scan, if the state is not Fixed, the AVIT is reopened.
{#avm-monitor-rem-prog__ul_ng1_dy2_ycb}

## Get more details from Veracode {#avm-monitor-rem-prog__section_epw_wbf_dbc}

Select Get More Details on application vulnerable items (AVITs) that have Veracode as the Source on the Application Vulnerable Item \[sn_vul_app_vulnerable_item\] table or from the list views in the Vulnerability Response Workspaces to view the following Veracode data.

* HTTP Source request and Source response details for Dynamic Application Security Testing (DAST) scans are displayed on the HTTP Request/Response related list.
* Solution recommendations from Veracode are displayed on the Findings related list.
* HTTP Source request, Source response, and recommendations are displayed on the Details tab In the Vulnerability Response Vulnerability Response workspaces.
* The Description column is supported on the Application Vulnerable Item \[sn_vul_app_vulnerable_item\] table.
{#avm-monitor-rem-prog__ul_k1l_hcf_dbc}

