---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Preparing the Common Vulnerability Reporting Framework (CVRF) solution integration

# Preparing the Common Vulnerability Reporting Framework (CVRF) solution integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the Setup Assistant to prepare for implementing a solution intelligence integration
for all the vendors that support the Common Vulnerability Reporting Framework (CVRF) data
format.

## Before you begin {#prepare-cvrf-solution-integration__section_dsn_4dz_slb}

To integrate with the vendors that provide the solutions, ensure you perform the tasks in the
following checklist. You can print the checklist and verify the items listed are completed
before you install the application.
{#prepare-cvrf-solution-integration__table_qby_jng_tlb__entry__2}

| Task | Description |
|-|-|
| Figure 1. Dependent applications ![Checkbox image.]() | Verify that the following applications are installed from the ServiceNow Store: * Vulnerability Solution Management: For more information about installing Vulnerability Solution Management, see [Install Vulnerability Response third-party applications using Setup Assistant](https://servicenow-prod.fluidtopics.net/4SVUHu2n7I65KBpfqP4EBg "Install the third-party integration applications you have entitlement for in Vulnerability Response using the Setup Assistant.") and [Install the Solution Management for Vulnerability Response application](https://servicenow-prod.fluidtopics.net/y_INCI~k10rb44Ipf472Ew "Before you can use the Solution Management for Vulnerability Response feature of Vulnerability Response in your instance, you must complete the installation of the Vulnerability Solution Management application. This application is available as a separate subscription in the ServiceNow Store."). * Vulnerability Response: For more information about installing and activating the Vulnerability Response application, see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). This integration requires version 16.1 of Vulnerability Response or later. {#prepare-cvrf-solution-integration__ul_tz4_lb2_tpb} |
| Figure 2. Third-party account credentials ![Checkbox image.]() | Verify you have any third-party account credentials available. They are required to edit some solution integrations. |
| Figure 3. Vendor authentication ![Checkbox image.]() | Verify that you have authenticated the vendors for import of solutions using the APIs. For more information on how to authenticate vendors, see [Configure Connection and Credential aliases](https://servicenow-prod.fluidtopics.net/Ti7v7wZRYqFZqkJrlqowDQ "Configure Connection and Credential aliases to authenticate vendors. In advisory parsing, third-party vendors are authenticated."). If you do not want to configure an API-based vendor, you can skip this step. |
| Figure 4. Customization of flow and flow action ![Checkbox image.]() | If you want to configure an API-based vendor other than Cisco, then you must customize the flow and flow action for extracting a unique key and CVRF URL from the response of an advisory. Note: Publishing CVRF URL is not standard across vendors. To customize the flow for vendors other than Cisco, see [Configure a Common Vulnerability Reporting Framework vendor other than Cisco](https://servicenow-prod.fluidtopics.net/3Uq9TFyVpcZJPMdK4rrpAw "Configure a Common Vulnerability Reporting Framework (CVRF) vendor other than Cisco with API support."). You can skip this step if they do not want to configure vendors other than Cisco. By default, the flow for Cisco has been shipped with the application. |
| Figure 5. Roles ![Checkbox image.]() | Verify that you have an admin group or user who can manage the integration. If not assigned, the admin assigns the vulnerability admin (sn_vul.vulnerability_admin) and other roles. |
[Table 1. Integration preparation checklist]

{#prepare-cvrf-solution-integration__table_qby_jng_tlb}

