---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response Integration with Black Duck

# Vulnerability Response Integration with Black Duck {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Vulnerability Response integration with Vulnerability Response Integration with Black Duck uses the data that is imported from the Black Duck Software Composition Analysis (SCA) tool to help you determine the impact and priority of the flaws in your
code.

## Integration overview {#vulnerability-response-integration-blackduck-overview__section_gvh_d4d_gbc}

With the Vulnerability Response Integration with Black Duck, you can collect SCA and make that data available to the ServiceNow AI Platform. Starting with v22.0.5 of Vulnerability Response, you can import the SCA vulnerabilities data to your instance so that you can identify the vulnerabilities in your software applications. For more information, see [Exploring Software Bill of Materials](https://servicenow-prod.fluidtopics.net/8LjPHeECHwD3bz2tvjiDFg "Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.").

A shared API ingests the SCA data.  
Note:  
Each integration record has a configured run-as user. The default value for this user is VR System. Don't change this value.

Every day, scheduled jobs invoke the integrations automatically in the order that they're listed. You can also execute individual scheduled jobs manually. Scheduled jobs simplify the vulnerability remediation life cycle by keeping
the instance synchronized with other vulnerability management systems.

## Available versions {#vulnerability-response-integration-blackduck-overview__section_pgg_fqd_gbc}

{#vulnerability-response-integration-blackduck-overview__table_ygm_4qd_gbc__entry__2}

| Release version | Release notes |
|-|-|
| If you intend to upgrade to a version that is compatible with Unified Security Exposure Management (USEM), please select a version starting with 30.x when installing or upgrading. | [Application Vulnerability Response release notes](https://www.servicenow.com/docs/access?context=secops-app-vuln-resp-rn&version=australia&pubname=australia-release-notes&ft:locale=en-US) |
| If you do not intend to upgrade to a version that is compatible with Unified Security Exposure Management (USEM), please select a version below 30.x when installing or upgrading. |   |
[Table 1. Black Duck Integration available versions]

{#vulnerability-response-integration-blackduck-overview__table_ygm_4qd_gbc}

## User group and roles {#vulnerability-response-integration-blackduck-overview__section_ecv_drd_gbc}

The Vulnerability Response Integration with Black Duck is installed by a user with the admin role and is configured by a member of the App-Sec Manager group. For more information, see the [Application Vulnerability Response user groups and roles](https://servicenow-prod.fluidtopics.net/pNl52AMjKjWmG3S5Q_qwiA#avm-manage-roles "Before you can successfully remediate vulnerabilities with Application Vulnerability Response (AVR), you must assign users to user groups.").

For integration run statuses, see [View the Vulnerability Response Integration with Black Duck import run status](https://servicenow-prod.fluidtopics.net/W5wRwBt3KYCUZ~MIBjLy1w "Verify the success of your integration runs, locate any issues, and confirm your remediation decisions by viewing the Vulnerability Integration Runs related list.")

To view data in the third-party vulnerabilities, see [View vulnerability libraries](https://servicenow-prod.fluidtopics.net/IZq57UW~KW0S4rDI9HTfsQ "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.").

