---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Importing data with the NVD and CWE integrations and managing third-party libraries

# Importing data with the NVD and CWE integrations and managing third-party libraries {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

If not already installed, download and run the NVD integration and run the CWE
scheduled job as part of your initial setup of Vulnerability Response and prior to importing
vulnerability data into your instance with a third-party scanner product. The Vulnerability
Response Integration with NVD is available on the ServiceNow Store.

## Ingesting CWE and NVD data {#c_NVDAndCWEDataImport__section_bf2_vrj_tvb}

Imported data from the NVD and CWE integrations are used to enrich the vulnerability data
in your instance and help you decide whether to escalate remediation for a vulnerability,
vulnerable item, or remediation task. After an initial import, you can update library
records on-demand or configure a scheduled job to update records regularly. Vulnerability Response stores them under Libraries.

The Common Vulnerability Scoring System (CVSS), included in NVD and third-party entries,
captures the main characteristics of a vulnerability. Vulnerability Response uses CVSS
data to produce a normalized value reflecting vulnerability severity. When the severity is
computed, the vulnerability provides a better understanding of the risk posed by this
vulnerability to your organization. Severity helps you assess and prioritize vulnerability
remediation.

If this is your first installation of Vulnerability Response, or prior to ingesting data
for the first time with a third-party scanner product:

1. Perform an initial import of CWE data with the CWE Comprehensive 2000 Integration.See
   [Configure and run the scheduled job for updating CWE records](https://servicenow-prod.fluidtopics.net/aRo8fssRnJZRi2wmZ1CNUQ "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.")
   for more information. You perform CWE updates On Demand from the
   integration record by default, and you must configure it if you want it to run as a
   scheduled job.

   Nota:  
   Schedule the CWE update to run prior to the NVD database update. The default day for the NVD update is Weekly on Monday.
2. Verify the Vulnerability Response Integration with NVD application is installed, and data from the NIST National Vulnerability Database Integration - API (CVE only) or the NIST National Vulnerability Database Integration - API (CVE and CPE) is successfully imported.

   Activation of this plugin on production instances may require a separate
   license. After it is installed, the NIST National Vulnerability Database Integration -
   API (CVE only) integration is activated by default. It runs daily. See [Understanding the NVD integrations](https://servicenow-prod.fluidtopics.net/9vRipztMoAT6rqAb9UQmsA "The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.") and
   [Install the Vulnerability Response Integration with the NIST National Vulnerability Database](https://servicenow-prod.fluidtopics.net/N0bk4GvI~Uc18kBaraeKNA#install-nvd "Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.") for more
   information.
3. Third-party libraries are updated as scheduled jobs. Refer to your integration documentation at [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/zQoHKjiBYFkRQWdwaz7MMw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") for more information about third-party integrations.
{#c_NVDAndCWEDataImport__ol_dkg_bsj_tvb}

## Viewing imported vulnerability data and vulnerable items {#c_NVDAndCWEDataImport__section_azq_dsj_tvb}

The following libraries are available:{#c_NVDAndCWEDataImport__table_hwd_bxl_dbb__entry__2}

| Libraries | Description |
|-|-|
| NVD | List of vulnerabilities found by NVD and includes security checklists, security-related software flaws, misconfigurations, product names, and impact metrics including exploits. |
| CWE | List of community-developed software weakness types. Each CWE record also includes an associated knowledge article that describes the weakness. You cannot escalate a vulnerability from the Common Weakness Enumerations screen, it is for reference only. |
| Third-party | List of imported third-party vulnerabilities in your instance. Contains a list of related references, vulnerable items, exploits, and CVEs. |
[ ]

{#c_NVDAndCWEDataImport__table_hwd_bxl_dbb}
**Tarefas relacionadas**   

* [View Vulnerability Response vulnerability libraries](https://servicenow-prod.fluidtopics.net/IZ7Jvo_ZQblCN0enyXI9xg "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.")

