---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Application Vulnerability Response references

# Application Vulnerability Response references {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The following terms are used in Application Vulnerability Response.

[Application Vulnerable items (AVIs)](https://servicenow-prod.fluidtopics.net/2jK7cd9PJsH~xbJW_IAlVQ "Application vulnerable items (AVITs) are automatically created during third-part vulnerability integration imports.")
:   Pairings of vulnerability entries and potentially vulnerable applications in your company environment.

[Assignment Rules](https://servicenow-prod.fluidtopics.net/zShzOXv6WwflHdQqFPBb0w "Automatically assign application vulnerabilities based on application tags, or any of the assignment groups in the Configuration Item [cmdb_ci] or platform assignment groups, to reduce the mean time to assignment.")
:   Rules used to assign AVIs based on your defined criteria.

[Common Platform Enumeration (CPE)](https://nvd.nist.gov/products/cpe)
:   A NIST NVD structured naming scheme for information technology systems, software, and packages.

[Common Vulnerabilities and Exposures (CVE)](https://cve.mitre.org/)
:   Dictionary of publicly known information-security vulnerabilities and exposures.

[Common Weakness Enumeration (CWE)](https://cwe.mitre.org/)
:   List of community-developed software weakness types.

[Integrations](https://servicenow-prod.fluidtopics.net/r93WHsyNRy7m1s7pRtbYpw "Vulnerability Response includes support for third-party integrations.")
:   Scheduled jobs that pull report data from CWE or a third-party system, such as Veracode, to retrieve vulnerability data.  
    Note:  
    If the NIST National Vulnerability Database integration in Vulnerability Response is activated and configured, CVE enrichment is available for CWEs but not required. For information on the NIST National Vulnerability Database integration, see [Importing data with the NVD and CWE integrations and managing third-party libraries](https://servicenow-prod.fluidtopics.net/SDp7vDWErXHrLtUOsZ_~qw "If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.").

[National Vulnerability Database (NVD)](https://nvd.nist.gov/)
:   U.S. Government repository of standards-based vulnerability management data represented using the Security Content Automation Protocol (SCAP).

[Remediation Target Rules](https://servicenow-prod.fluidtopics.net/rrUEZGyQAT~Ipz2iWiKYEQ "Application Remediation Target Rules define the expected timeframe for remediating application vulnerable items (AVIs), providing a timeframe for remediating the vulnerability itself. For example, if an application vulnerable item contains a critical risk rating then the vulnerability on that item needs to be fixed within 15 days.")
:   Rules used to assign AVIs target dates for remediation based on your defined criteria.

[Vulnerability Calculators](https://servicenow-prod.fluidtopics.net/lh8BvObOHho_kLRstHZzcA "Application vulnerability calculators automate calculating initial risk values for the fields on application vulnerable items (AVIs). Risk calculations offer insight into prioritizing remediation. The condition for each calculator is evaluated in order, and the first matching calculator is used.")
:   Calculators used to prioritize and categorize application vulnerabilities based on your defined criteria.

