---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an application vulnerability entry

# Create an application vulnerability entry {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an application vulnerability entry for the vulnerability specified for the penetration test finding. Application vulnerabilities are vulnerabilities on the custom software applications.

## Before you begin

Role required: Ethical Hacker

## About this task

Application Vulnerability Response relates a vulnerability to an application to create the penetration test finding. These findings are manually-created application vulnerable items (AVIs). You can reuse an existing entry or create one manually for each vulnerability during penetration testing.

## Procedure

1. Navigate to AllApplication Vulnerability ResponseLibrariesThird-Party.
2. On the Application Vulnerability Entries page, select New.
3. On the form, fill in the fields.  
   {#pen-test-create-app-vul-entry-avm__table_uff_fjr_qqb__entry__2}

   | Field | Description |
   |-|-|
   | ID | Identifier for this vulnerability entry. |
   | Severity | Normalized degree of severity of this vulnerability. Severity maps are provided for NVD and with ServiceNow third-party integrations. For more information on creating or adjusting severity maps, see [Map the severity of an application vulnerable item automatically](https://servicenow-prod.fluidtopics.net/NuRM3JHLq~b8ccyHg3~Bkg "Application Vulnerability Response severity mapping transforms third-party source severity fields to recognizable fields within Vulnerability Response."). |
   | Primary CVE | Reference to the Common Weakness Enumeration element that this vulnerability best fits into. |
   | Category name | Classification provided by the third-party integration. Aids in assignment. |
   | Vulnerability Details ||
   | Attack vector | Most vulnerable attack vector for this vulnerability. |
   | Attack complexity | Metric that describes the conditions beyond the attacker's control that must exist to exploit the vulnerability. |
   | Scope | Metric to measure the ability of a software vulnerability to impact resources beyond its means. |
   | Integrity | Metric to measure the impact to the integrity of a successfully exploited vulnerability. |
   | CVSS Vector | Open framework to capture the characteristics and severity of software vulnerabilities. |
   | Privileges required | Level of privileges an attacker must possess before successfully exploiting the vulnerability. |
   | User interaction | Requirement for human interaction to successfully exploit a vulnerability. |
   | Confidentiality | Impact to the confidentiality of the information resources due to a successfully exploited vulnerability. These resources are managed by a software component. |
   | Availability | Impact to the availability of the impacted component resulting from a successfully exploited vulnerability. |
   | CVSS Base Score | Numeric (0-10) representation of the severity of an application vulnerability entry. |
   | Threat | Description of the threat from this vulnerability. |
   | Mitigation description | Description of the steps to mitigate the vulnerability. |
   [Table 1. Application Vulnerability Entry form (Penetration test view)]

   {#pen-test-create-app-vul-entry-avm__table_uff_fjr_qqb}
4. To save the form, select Submit.  
   Note:  
   AVEs are created in the Application Vulnerability Entry (sn_vul_app_vul_entry) table. The Application Vulnerability Entry table is a child of the Vulnerability Entry (sn_vul_entry) table. Hence, the AVEs created are added to the Vulnerability Entry table as well.

*[\>]: and then


