---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request an exception for a container vulnerable item

# Request an exception for a container vulnerable item {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Request an exception for a container vulnerable item (CVIT) that can't be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn't available for a machine.

## Before you begin

Role required: Developer Group

## About this task

You can request an exception for multiple CVITs simultaneously using the Bulk Edit feature in the Vulnerability Manager Workspace. For more information, see [Request bulk exception in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/FrQxWrSlJMo6g0Fuc2z~EQ "Request an exception for multiple records (VITs, AVITs, CVITs or TRs) concurrently using the bulk edit feature instead of manually selecting each record.").

## Procedure

1. Navigate to Container Vulnerability ResponseContainer Vulnerable ItemsAll.
2. Select the item that you want to request an exception for.  
   The selected item must be in Open or Under Investigation state.
3. On the Container Vulnerable Item form, click Request Exception.
4.
   1. On the form, fill in the fields.  
      {#cvr-raise-exception__table_kxh_gh2_4lb__entry__2}

      | Field | Description |
      |-|-|
      | Until | Date on which the exception request expires. This date must be within the duration selected in the AllContainer Vulnerability ResponseAdministrationException Management screen. When the exception request expires, the group reverts to its Open state. Note: Starting with version 1.2 of Container Vulnerability Response, if a vulnerable item was deferred for remediation by using the exception management feature, then in case it is reopened by the scanner, the deferral date set on the vulnerability will still persist. To enable this functionality, set the value of the system property sn_vul.container.auto_defer_cvit_in_active_exception_window to true. Also, the deferred until date persists even after the CVIT gets closed or the exception expires. The role required is sn_vul_container.manage_exception_configuration for both read and write. |
      | Reason | Reason for the exception. Choices are as follows: * Risk Accepted * Awaiting Maintenance Window * Fix Unavailable * Mitigating Control in Place * Other {#cvr-raise-exception__ul_ifx_15g_3nb}To see how to add new reason choices, see [Define a policy reason mapping](https://servicenow-prod.fluidtopics.net/GqR9txt8GlzWjVSPendUoA "Define reason choices to be available to any user who requests an exception."). |
      | Additional information | Details that are related to the reason why this request is being made. This field is to be updated by the remediation owner. |
      [Table 1. Request Exception form]

      {#cvr-raise-exception__table_kxh_gh2_4lb}
   2. Submit the exception request by clicking Request Approval.  
      The state of the container vulnerable item changes to In Review. Use the State Change Approval tab to track the status of the exception request.
   {#cvr-raise-exception__substeps_mb3_q24_hvb}
{#cvr-raise-exception__steps_o4r_jpy_flb}

*[\>]: and then


