---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Identify and escalate security issues using CWE

# Identify and escalate security issues using CWE {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

View the library of Common Weakness Enumeration (CWE) records from the National Vulnerability Database (NVD) to understand how they relate to the Common Vulnerability and Exposure (CVE) records. Then use this information to
match the vulnerable software entries to a Software Asset Management discovery model.

## Before you begin

Role required: sn_vul.vulnerability_write

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information about managing granular roles, see [Manage persona and granular roles for Vulnerability Response](https://servicenow-prod.fluidtopics.net/WeKNf9YHNMJmJIA6yCsRvA "After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.").

## Procedure

1. Navigate to AllVulnerabilityLibrariesCWE.  
   A list of vulnerable software downloaded is shown.
2. Click a CWE software record to view vulnerability information.
3. Click the following related lists to get more information for identifying vulnerabilities.

   | Related list | Description |
   | Vulnerable Items | Lists any vulnerable items, which consist of pairings of a potentially vulnerable configuration item and software. To get more information about a pairing, click the information icon (![Information icon]()). Note: If software is removed, any associated vulnerable items are closed and removed from the Vulnerable Items related list. |
   | Vulnerability Entries | Lists vulnerability entries for the selected software record. Click a record to view its details. |
   |-|-|

   {#escalate-sec-issue-CWE__choicetable_hgr_s3j_dt}  
   If vulnerabilities were identified and vulnerable items were created, you can [Resolve remediation tasks](https://servicenow-prod.fluidtopics.net/PiQ4It8j3oikPwb8I01MRA "The flexibility inherent in Vulnerability Response allows you to remediate vulnerabilities in whatever way suits your security organization."), as needed.
{#escalate-sec-issue-CWE__steps_cwr_lx4_15}

*[\>]: and then


