---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Application Vulnerable Item (AVI) states

# Application Vulnerable Item (AVI) states {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 min. de leitura

Application Vulnerability Response offers a state model for the status of your
application vulnerable items (AVIs), at any given time. Knowing how each state relates to and
affects each other helps you to determine when and how to remediate your AVIs.

## Application Vulnerable Item states {#avm-states__VulnGrpStates}

Understanding how states work helps with creating or editing application vulnerable item (AVI) rules. AVIs have several possible states that are mapped from imported Remediation status from the third-party integration.
In an AVI, the State field is read-only.
{#avm-states__table_tzf_znm_tsb__entry__2}

| State | Description |
|-|-|
| Open | State upon creation. From this state you can: V16: Get More Details :   Get the following information about an AVI imported from Fortify: * Vulnerability summary * Vulnerability explanation * Recommendation * References * Request * Response {#avm-states__ul_qsk_3pm_tsb} V16: Mark as false positive :   Mark an item as false positive if the scanner reports that a vulnerability exists in the system, but in reality there is no vulnerability. V16: Request exception :   Request an exception, a reopen (Until) date, a reason, and optionally, provide addition information. Defers the remediation of the item until the date till which an exception is requested. V15: Close :   Select the Closed state, a reason from the Close Vulnerable Item dialog box, and provide addition information. Closes the AVI. V15: Resolve :   Mark an open AVI as Resolved to move it to a resolved state. You must add resolution notes in the Resolve Application Vulnerable Item dialog box. |
| Deferred | V15: This is triggered by the Request Exception option. As part of the approval workflow, the Deferred state is In Review and cannot be closed until approved. From this state you can: V16: Get More Details :   Get the following information about an AVI imported from Fortify: * Vulnerability summary * Vulnerability explanation * Recommendation * References * Request * Response {#avm-states__ul_izn_b1p_5sb} Reopen :   Transitions a closed or resolved AVI back to an Open state. Close :   Select the Closed state, a reason, and provide addition information. Closes the AVI. |
| Under Investigation | Select this option from the State list. From this state you can: V20.0 :   Manually transition a remediation task or AVI record to Awaiting Implementation. V16: Get More Details :   Get the following information about an AVI imported from Fortify: * Vulnerability summary * Vulnerability explanation * Recommendation * References * Request * Response {#avm-states__ul_ulx_w1p_5sb} V16: Mark as false positive :   Mark an item as false positive if the scanner reports that a vulnerability exists in the system, but in reality there is no vulnerability. V16: Request exception :   Request an exception, a reopen (Until) date, a reason, and optionally, provide addition information. Defers the remediation of the item until the date till which an exception is requested. V15: Close :   Select the Closed state, a reason from the Close Vulnerable Item dialog box, and provide addition information. Closes the AVI. V15: Resolve :   Mark an open AVI as Resolved to move it to a resolved state. You must add resolution notes in the Resolve Application Vulnerable Item dialog box. |
| Awaiting Implementation | You can only transition records to this state manually by selecting Awaiting Implementation from AVI and remediation task records in the Under Investigation state. From this state you can: Open :   Transitions AVI back to an Open state. Under Investigation :   Get more information for resolution. Transitions to Under Investigation. Resolve :   Mark an open AVI as Resolved to move it to a resolved state. You must add resolution notes in the Resolve Application Vulnerable Item dialog box. Close :   Select the Closed state, a reason from the Close Vulnerable Item dialog box, and provide addition information. Closes the AVI. In this state, Transition a record into Awaiting Implementation when your research and work on a task is complete and although a fix is ready for implementation, it is not yet available. Set the Remediation Commitment date and Remediation plan fields. After implementation, you resolve or close the records. |
| Resolved | Triggered from the Resolve button. From this state you can: V16: Get More Details :   Get the following information about an AVI imported from Fortify: * Vulnerability summary * Vulnerability explanation * Recommendation * References * Request * Response {#avm-states__ul_skw_rbp_5sb} Reopen :   Transitions back to an Open state. Close :   Select the Closed state, a reason, and provide addition information. Closes the group. Notes and Resolution information appear under the Notes tab. |
| Closed | Triggered from the Close button. From this state you can: Reopen: Transitions back to an Open state. |
[Tabela 1. Application Vulnerability Response state flow diagram]

{#avm-states__table_tzf_znm_tsb}  
Nota:  
Refer to the [Integrating Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/4sMSaVi577vChnewy5kdvg "Vulnerability Response includes support for third-party integrations.") with other applications for understanding different integrations that sourced the AVI.

## Application Remediation Task states {#avm-states__section_g1d_vdb_ccc}

From the creation to closure of an Application Remediation Task, the Application Remediation Task transitions through various states during the entire remediation process.

The state precedence is as follows:

ClosedDeferredResolvedIn ReviewAwaiting ImplementationUnder InvestigationOpen

The state transition happens as you perform various actions such as Defer, Open, Close, etc.

The actions you can perform on an Application Remediation Task at a specific state is similar to that of a Host Remediation Task. Hence, for more information, see the [Vulnerability Response remediation task states](https://servicenow-prod.fluidtopics.net/C6yj1IVZriTW6fS8LzS05g "Third-party integrations import vulnerable item detection data that create new vulnerability items (VITs) or update existing VITs. Detection states update VIT states in so far as they’re Open or Closed.") and [State roll-up and roll-down scenarios](https://servicenow-prod.fluidtopics.net/VBbVGQsS3wJfmhcVrt7sSg "State roll-up and roll-down scenarios automatically sync the status of remediation tasks (RTs) and vulnerable items (VITs), ensuring real-time updates across both. This dynamic interaction reduces manual tracking, enhances accuracy, and provides users with an up-to-date view of progress, making vulnerability management more efficient and helping users make informed decisions quickly.") in the Vulnerability Response documentation.  
Nota:  
Starting with v23.0 of Vulnerability Response, the Close button has been removed to ensure that the closure of the Remediation task is driven by the scanner.

