---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Invicti Vulnerability Integration state mapping

# Invicti Vulnerability Integration state mapping {#ariaid-title1}

* Release version: Australia
* 
* Updated July 6, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The following source states from the Invicti Vulnerability Integration and their target states in your instance are listed in the following table.
Note:  
If you have selected Manage exceptions and Manage False Positives to manage the state transitions for these types of application vulnerable items (AVITs) in your ServiceNow AI Platform® instance described in [Configure the Invicti Vulnerability Integration](https://servicenow-prod.fluidtopics.net/bXccrWLlcwmVs~BCf0aM8A "Before you run the integration on your instance, the installation and configuration steps must be completed so the Invicti Vulnerability Integration properly works with the Application Vulnerability Response feature of Vulnerability Response."), the source states that are imported from Invicti that might be mapped to deferred or closed states in your instance are mapped to the Open state.
{#invicti-mapping__table_dw3_snj_vzb__entry__3}

| Invicti source states | Description of source states | Target state in the ServiceNow AI Platform |
|-|-|-|
| Present | The Issue is identified. | Open |
| Present, AcceptedRisk, Revived | The Issue has been considered and is marked as a low risk vulnerability. | Deferred |
| Present, False Positive | The Issue has been considered and is marked as not a genuine vulnerability. | Closed |
| FixedUnconfirmed, Fixed Unconfirmed | The Issue has been fixed but not confirmed by Invicti Enterprise. | Resolved |
| Fixed (Confirmed), FixedConfirmed, FixedConfirmed, AcceptedRisk, FixedConfirmed, False Positive | The Issue has been fixed and confirmed by Invicti Enterprise and no further action is required. | Closed |
| Fixed (Can't Retest) | The Issue has been identified but Invicti cannot retest to confirm whether the Issue has been fixed or not. | Resolved |
| Revived | The issue was fixed in previous scans but has been found again. | Open |
| Deferred, Ignored | The Issue was ignored by the user. In Invicti Enterprise, to ignore an issue, a user updates its status to "accepted risk". | Risk Accepted |
[Table 1. Invicti source states and their corresponding ServiceNow AI Platform states]

{#invicti-mapping__table_dw3_snj_vzb}

## Application release mapping {#invicti-mapping__section_iff_j1t_d1c}

|-|-|
| Source Field | Target field on ServiceNow AI Platform |
| ID | source_app_id |
| CreatedAt | app_creation_date |
| UpdatedAt | app_updation_date |
| Name | app_name |
| RootUrl | Source_additional_info |
| Description | description |
| Tags | Tags |
[ ]

{#invicti-mapping__table_dj4_41t_d1c}

## Vulnerability mapping {#invicti-mapping__section_tfd_x1t_d1c}

|-|-|
| Source Field | Target field on ServiceNow AI Platform |
| Type | Category name |
| Vulnerability detail | Summary |
| Impact | Threat |
| Source references | Web references |
| Source recommendation | Solution |
| Type | source_entry_id/ID |
| Severity | source_severity |
| Classification\["Cwe"\] | CWE list |
| CvssVectorString | CVVS v3 fields |
[ ]

{#invicti-mapping__table_vhf_y1t_d1c}

## Scan summary mapping {#invicti-mapping__section_p2r_bbt_d1c}

|-|-|
| Source field | Target Field |
| Source | Source |
| TotalVulnerabilityCount | Detected_flaw_count |
| Initiated date | Dynamic scan date |
| id | source_scan_id |
[ ]

{#invicti-mapping__table_o3t_dbt_d1c}

## Application vulnerable item (AVIT) mapping {#invicti-mapping__section_olw_fbt_d1c}

|-|-|
| Source Field | Target field on ServiceNow AI Platform |
| Type | Scan type |
| Website ID | Source app ID |
| ID | Source AVIT ID |
| Last seen date | Last found |
| First seen date | First found |
| Last updated date | Last scan date |
| parameters | Affected parameter |
| URL | Affected URL |
| Severity | Source severity |
| Url | Source link |
| Vulnerability detail | Source vulnerability summary |
| External references | Source references |
| Remedy + Remedy references | Source recommendation |
| State | Source remediation status |
| Impact | Source vulnerability explanation |
[ ]

{#invicti-mapping__table_tsy_gbt_d1c}

