---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request an exception for an application vulnerable item

# Request an exception for an application vulnerable item {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Request an exception for an application vulnerable item that cannot be remediated immediately. For example, as a developer, you can request an exception if a patch is not available for a machine.
Important:  
You can request exceptions for an application vulnerable item and a remediation task from the Vulnerability Manager Workspace and IT Remediation Workspace. For more information, see [Request exceptions for remediation tasks and records in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/bWo4zdNcYMgNqM8grmyNNw "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.") and [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/u8048LRMppDaxV9c9jKGkg "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").

## Before you begin

Role required: Developer Group

## Procedure

1. Navigate to Application Vulnerability ResponseApplication Vulnerable ItemsAll and select the item that you want to request an exception for.  
   The selected item must be in Open or Under Investigation state.  
   Note:  
   Starting from v21.0 of Application Vulnerability Response, the previous state of an application vulnerable item is stored in the backup_state field.
2. On the Application Vulnerable Item form, click Request Exception.  
   Note:  
   Depending on whether Vulnerability Response is selected or GRC: Policy and Compliance Management in the Application Vulnerability ResponseException Management screen, the Request Exception form changes. If GRC: Policy and Compliance Management, see [Request an exception for application vulnerabilities using GRC: Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/sfj3W64Fv9Mgem~fs7~a4Q "Request policy exceptions using the GRC policy exception management capability in the Policy and Compliance Management application from within Application Vulnerability Response.")
3. If Vulnerability Response is selected in the Exception Management screen, fill in the fields in the Request Exception form.  
   {#avr-raise-exception__table_kxh_gh2_4lb__entry__2}

   | Field | Description |
   |-|-|
   | Until | Date on which the exception request expires. This date must be within the duration selected in the AllApplication Vulnerability ResponseAdministrationException Management screen. When the exception request expires, the group reverts to its Open state. Note: Starting with version 18.0 of Application Vulnerability Response (AVR), a deferred application vulnerable item can be closed and reopened by a scanner. If the item reopens before the exception window expires, the state of the AVIT reverts to deferred state honouring the active exception window. To enable this functionality, set the value of the system property sn_vul.auto_defer_avit_in_active_exception_window to true. Also, the deferred Until date persists even after the AVIT gets closed or the exception expires. The role required is sn_vul.app_manage_exception_configuration for both read and write. |
   | Reason | Select the Reason. Choices are: * Risk Accepted * Awaiting Maintenance Window * Fix Unavailable * Mitigating Control in Place * Other {#avr-raise-exception__ul_ifx_15g_3nb}To see how to add new reason choices, refer [Define policy reason mapping](https://servicenow-prod.fluidtopics.net/VqompuLYlCNZl~dKwV2iTg "You can define the reason choices to be available to any user who requests an exception."). |
   | Additional information | Details that are related to the reason why this request is being made. This required field is to be updated by the remediation owner. |
   [Table 1. Request Exception form]

   {#avr-raise-exception__table_kxh_gh2_4lb}
4. Click Request Approval to submit the exception request.  
   The state of the application vulnerability item changes to In Review. Use the State Change Approval tab to track the status of the exception request.
{#avr-raise-exception__steps_o4r_jpy_flb}

*[\>]: and then


