---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Assess your exposure to vulnerable software

# Assess your exposure to vulnerable software {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

You can provide the publisher and product information in the Exposure Assessment module to assess your zero-day (current day) exposure of your assets to vulnerable software using the ITSM Software Asset Management (SAM) Foundation application.
Important:  
You can perform the exposure assessment by software and Common Vulnerabilities and Exposures (CVE) to leverage the additional capabilities in the Vulnerability Assessment Workspace. For more information, see [Explore the Vulnerability Assessment Workspace](https://servicenow-prod.fluidtopics.net/u8sK2NCOophqngLNqHw_8w "The Vulnerability Assessment Workspace is designed for the Vulnerability event manager to perform exposure assessment, and proactively manage critical vulnerability events especially during the critical vulnerability events such as a zero-day event.").

## Before you begin

Role required: vulnerability admin (sn_vulnerability_write)

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information about managing granular roles, see [Manage persona and granular roles for Vulnerability Response](https://servicenow-prod.fluidtopics.net/WeKNf9YHNMJmJIA6yCsRvA "After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.").  
Have the following information available about the vulnerable software that you want to assess:

* Publisher
* Version
* Product
* Edition
{#vr_sw_expsure_task__ul_hb2_g5q_2jb}

## About this task

For more information on system requirements, see [Configure the Vulnerability Exposure Assessment](https://servicenow-prod.fluidtopics.net/Lt17fiLzyFW2wWmxwEywpw "Assess the zero-day (current day) exposure of your assets to vulnerable software with the Vulnerability Exposure Assessment application.").

View the software exposure assessment module and create and edit exposure assessment records on-demand for vulnerable software in your ServiceNow AI Platform® instance.

You manage the vulnerability response activities for a large operation responsible for many assets. The Security Operations Center (SOC) in your operation contacts you about a version of software that they've learned is
vulnerable. You discover that a scan of your assets was recently completed and didn't find this vulnerability. The SOC team learned about this vulnerability from a reliable source outside of the National Vulnerability Database
(NVD), Common Weakness Enumeration (CWE), or the other third-party libraries in your instance, and you're concerned that your vulnerability scanner hasn't yet added the plugin for it.

You are confident that the data for this vulnerability will be updated in the NVD and imported soon so that your scanner can catch this vulnerability in the next scan, but because you are concerned about the scope of your
potential exposure, you want to determine today if you have assets in your network that have this software installed.

Starting with v23.0 of Vulnerability Response, if you have the Pro or Enterprise subscription, you are redirected to the Exposure Assessment page in the Workspaces based on your role on selecting the Exposure Assessment link in the All menu. For more information, see [Configure the Vulnerability Exposure Assessment](https://servicenow-prod.fluidtopics.net/Lt17fiLzyFW2wWmxwEywpw "Assess the zero-day (current day) exposure of your assets to vulnerable software with the Vulnerability Exposure Assessment application.").

## Procedure

1. To create a new exposure assessment, navigate to AllVulnerability ResponseVulnerability ScanningExposure Assessment.  
   The Exposure Assessments list is displayed.
2. Select New.  
   The Exposure Assessment form is displayed.
3. Fill out the form.  
   {#vr_sw_expsure_task__table_qcf_n5q_2jb__entry__2}

   | Field | Description |
   |-|-|
   | Publisher | Name of the software publisher. |
   | (Optional) Version | Enter the version number to help you narrow the search on your assets. |
   | Product | Name of the software product. |
   | (Optional) Edition | Enter the edition to help you narrow the search on your assets. |
   | CI filter | Use the choice lists for the Configuration Item (CI) filter to limit your search to specific configuration items (assets). For example, you can submit a query for only active assets that may have this software installed: <kbd class="ph userinput">Operational status is Operational</kbd> |
   [ ]

   {#vr_sw_expsure_task__table_qcf_n5q_2jb}
4. Select Show Exposure.  
   The Exposure Assessment record with your discovery model and the software installation count on your assets as of the specific date is displayed.
5. Choose one to continue.

   | Option | Description |
   | Show Exposure | Add additional CI filter conditions and select Show Exposure to further refine your search results. |
   | Create Vulnerable Items | Create vulnerable items for the configuration items from your search results. If vulnerable items are successfully created, a remediation task is created for all the vulnerable items and displayed on the exposure assessment record. |
   | Delete | Delete this record and return to the Exposure Assessments list. A confirmation dialog is displayed. |
   |-|-|

   {#vr_sw_expsure_task__choicetable_gcz_mgr_2jb}
6. **Optional:** Create a vulnerable item for your search result.  
   Note:  
   After you create vulnerable items, you cannot alter the search criteria for this exposure record.
7. Alternatively, revise your filter conditions and further refine your search results.
8. To create vulnerable items, follow these steps:
   1. Select Create Vulnerable Items.  
      The Create Vulnerable Items dialog is displayed.
   2. Fill in the fields.  
      {#vr_sw_expsure_task__table_yn2_nzr_2jb__entry__2}

      | Field | Description |
      |-|-|
      | Using | Form the choice list, choose one to continue. * Existing vulnerability. To the right of the Vulnerability field, click the search icon. In the list that is displayed, select the CVE-ID, or enter search criteria to locate the existing CVE-ID, for example, CVE 2018-9120. Note: This can be a CVE-ID from a vulnerability database other than the NVD. * New vulnerability. Enter the CVE-ID for your new vulnerability in xxxx-xxxx, xxxx-xxxxx, or xxxx-xxxxxxx format. {#vr_sw_expsure_task__ul_ybb_c3r_2jb} |
      | Vulnerability summary (for new vulnerability only) | Enter a summary for the new vulnerability, for example, <kbd class="ph userinput">An attacker can execute script on an unsuspecting user's browser</kbd>. |
      [ ]

      {#vr_sw_expsure_task__table_yn2_nzr_2jb}

      The following images show examples of the completed form for an
      existing vulnerability and a new vulnerability.
      Figure 1. Existing vulnerability Figure 2. New vulnerability
   3. Select Create Vulnerable items.  
      The Exposure Assessment record is displayed with a status message which indicates that vulnerable items are being created.
   4. After a few seconds, at the top of the form, right-click in the gray banner to reload the page.  
      The new vulnerable items are displayed as shown in the following figure on the Assessed Vulnerable Items tab (531). The new remediation task created for these vulnerable items is displayed on the remediation task tab (1).  
      Note:  
      For this example, a remediation task is created according to the group rules and conditions from the remediation task rule called, Vulnerability. This group rule is the default remediation task rule that is installed with the Vulnerability Response product in your ServiceNow AI Platform® instance. In this example, the conditions of this group rule placed all the vulnerable items into a single remediation task. If you prefer to create more than one remediation task for the vulnerable items that match your exposure assessment search results, you may prefer to set up additional remediation task rules. Creating more remediation tasks may help you prevent creating remediation tasks with large numbers of vulnerable items. For more information about remediation task rules, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.") and [Create or edit Vulnerability Response remediation task rules](https://servicenow-prod.fluidtopics.net/gjnIR~u_kUymvXKMt0Lqng "After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.").
   {#vr_sw_expsure_task__substeps_lvz_4hr_2jb}
9. Choose one to continue.  
   {#vr_sw_expsure_task__table_ltk_dbs_2jb__entry__2}

   | Option | Description |
   |-|-|
   | Remediation tasks | With the Remediation Tasks tab selected, in the number column, click to open the record and review and assign the task for remediation. For more information on assignment groups, see [Creating groups](https://www.servicenow.com/docs/access?context=ua-creating-groups&version=australia&pubname=australia-platform-administration&ft:locale=en-US). |
   | Assessed Vulnerability Items | With the Assessed Vulnerable Items tab selected, in the Vulnerable item column, click to open the records and review and assign individual vulnerable items. |
   | Delete | Delete the exposure assessment record. A confirmation dialog is displayed. Note: If you delete the exposure record after you create vulnerability items, any vulnerable items that you create for this record that aren't related to another exposure record are automatically moved to the Closed state. The reason for closure is Cancelled. |
   |   ||
   [ ]

   {#vr_sw_expsure_task__table_ltk_dbs_2jb}

## What to do next

Respond to any zero-day (current day) threats based on your exposure assessment. For more information about remediation tasks and change management for Vulnerability Response, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.") and [Change management for Vulnerability Response](https://servicenow-prod.fluidtopics.net/rJLLQMfetmDSSTGbuH_CNw "As an IT remediation owner, you can create and manage change requests (CHG) directly from remediation tasks (RT) in the Vulnerability Response application. Change requests help you initiate and track change activities on your assets so that you can remediate your remediation tasks and their corresponding vulnerable items.").

*[\>]: and then


