---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Importing data with the NVD and CWE integrations and managing third-party libraries

# Importing data with the NVD and CWE integrations and managing third-party libraries {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Importing data with the NVD and CWE integrations and managing third-party libraries

This guide provides essential steps and information for ServiceNow customers regarding the integration of the National Vulnerability Database (NVD) and Common Weakness Enumeration (CWE) into the Vulnerability Response module.
These integrations enhance vulnerability data, aiding in the effective remediation of vulnerabilities identified by third-party scanning tools.
Show full answer Show less  

## Key Features

* **NVD and CWE Integration:** Importing data from NVD and CWE enriches vulnerability records, helping prioritize remediation efforts based on severity.
* **Common Vulnerability Scoring System (CVSS):** Utilized to assess vulnerability severity, facilitating informed decision-making about remediation.
* **Scheduled Updates:** Configure scheduled jobs for regular updates of library records, ensuring data remains current.
* **Integration Accessibility:** The NVD integration is available via the ServiceNow Store, and activation may require a separate license for production instances.

## Key Outcomes

By effectively utilizing these integrations, ServiceNow customers can:

* Enhance their vulnerability management processes with enriched data from NVD and CWE.
* Utilize CVSS data to better understand and prioritize vulnerabilities based on their risk to the organization.
* Maintain up-to-date vulnerability records through scheduled updates for both CWE and third-party libraries.
* Access a comprehensive list of vulnerabilities and associated resources within their instance, aiding in thorough vulnerability assessments.  
If not already installed, download and run the NVD integration and run the CWE
scheduled job as part of your initial setup of Vulnerability Response and prior to importing
vulnerability data into your instance with a third-party scanner product. The Vulnerability
Response Integration with NVD is available on the ServiceNow Store.

## Ingesting CWE and NVD data {#c_NVDAndCWEDataImport__section_bf2_vrj_tvb}

Imported data from the NVD and CWE integrations are used to enrich the vulnerability data
in your instance and help you decide whether to escalate remediation for a vulnerability,
vulnerable item, or remediation task. After an initial import, you can update library
records on-demand or configure a scheduled job to update records regularly. Vulnerability Response stores them under Libraries.

The Common Vulnerability Scoring System (CVSS), included in NVD and third-party entries,
captures the main characteristics of a vulnerability. Vulnerability Response uses CVSS
data to produce a normalized value reflecting vulnerability severity. When the severity is
computed, the vulnerability provides a better understanding of the risk posed by this
vulnerability to your organization. Severity helps you assess and prioritize vulnerability
remediation.

If this is your first installation of Vulnerability Response, or prior to ingesting data
for the first time with a third-party scanner product:

1. Perform an initial import of CWE data with the CWE Comprehensive 2000 Integration.See
   [Configure and run the scheduled job for updating CWE records](https://servicenow-prod.fluidtopics.net/eW08j7C7hKeJNiT7jgbPMg "Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.")
   for more information. You perform CWE updates On Demand from the
   integration record by default, and you must configure it if you want it to run as a
   scheduled job.

   Note:  
   Schedule the CWE update to run prior to the NVD database update. The default day for the NVD update is Weekly on Monday.
2. Verify the Vulnerability Response Integration with NVD application is installed, and data from the NIST National Vulnerability Database Integration - API (CVE only) or the NIST National Vulnerability Database Integration - API (CVE and CPE) is successfully imported.

   Activation of this plugin on production instances may require a separate
   license. After it is installed, the NIST National Vulnerability Database Integration -
   API (CVE only) integration is activated by default. It runs daily. See [Understanding the NVD integrations](https://servicenow-prod.fluidtopics.net/eFiXOlP4oTeyfPz4Q0roQA "The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.") and
   [Install the Vulnerability Response Integration with the NIST National Vulnerability Database](https://servicenow-prod.fluidtopics.net/tv6~nhoCd~2oDYSHAh_Kmw#install-nvd "Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.") for more
   information.
3. Third-party libraries are updated as scheduled jobs. Refer to your integration documentation at [Vulnerability Response integrations](https://servicenow-prod.fluidtopics.net/5tRtjEBZLs~2Uym3WljEBw "Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.") for more information about third-party integrations.
{#c_NVDAndCWEDataImport__ol_dkg_bsj_tvb}

## Viewing imported vulnerability data and vulnerable items {#c_NVDAndCWEDataImport__section_azq_dsj_tvb}

The following libraries are available:{#c_NVDAndCWEDataImport__table_hwd_bxl_dbb__entry__2}

| Libraries | Description |
|-|-|
| NVD | List of vulnerabilities found by NVD and includes security checklists, security-related software flaws, misconfigurations, product names, and impact metrics including exploits. |
| CWE | List of community-developed software weakness types. Each CWE record also includes an associated knowledge article that describes the weakness. You cannot escalate a vulnerability from the Common Weakness Enumerations screen, it is for reference only. |
| Third-party | List of imported third-party vulnerabilities in your instance. Contains a list of related references, vulnerable items, exploits, and CVEs. |
[ ]

{#c_NVDAndCWEDataImport__table_hwd_bxl_dbb}
**Related tasks**   

* [View Vulnerability Response vulnerability libraries](https://servicenow-prod.fluidtopics.net/JMOl4iNRK0~b7PHhzDFl1w "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.")

