---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Preparing for the Veracode Vulnerability Integration

# Preparing for the Veracode Vulnerability Integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

A successful Veracode Vulnerability Integration requires planning and the execution
of pre-integration tasks. Prepare for the integration by performing these tasks. The Veracode Vulnerability Integration assumes that you are familiar with the Veracode product and API.

## Before you begin

The Common Weakness Enumeration (CWE) integration is also used by Application Vulnerability Response and should be running prior to installing and configuring the Veracode Vulnerability Integration. It is installed with Vulnerability Response, by default.  
Note:  
NIST Vulnerability Database (NVD) data is not necessary to install the Veracode Application Vulnerability Integration, however they provide enrichment and would be useful to have. For information on NVD, see [Importing data with the NVD and CWE integrations and managing third-party libraries](https://servicenow-prod.fluidtopics.net/SDp7vDWErXHrLtUOsZ_~qw "If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.").

There is a configured run-as user for each integration record. The default value for
this user is VR.System. Do not change this value.

Role required: App-Sec Manager group

## About this task

Note:  
Before running the integration, make any necessary configuration changes based on your requirements.

Validate your instance sizing based on the number of application vulnerable items you expect to import. An undersized instance can lead to long load times. If you do not know the size of your instance, contact Customer Service and Support.

The Veracode Vulnerability Integration requires an API id and API key.

## Procedure

To create the API ID and key credentials:  
1. Log in to the Veracode Platform.
2. Go to the user account menu and select API Credentials.
3. Click Generate API Credentials.
4. Record your credentials for later use.
{#veracode-prerequisites__ol_d4n_v3g_tlb}

