---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# Fortify Application Vulnerability Integration release notes

# Fortify Application Vulnerability Integration release notes {#ariaid-title1}

Release version: Store  
Updated June 11, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Fortify Application Vulnerability Integration release notes

The Fortify Application Vulnerability Integration on the ServiceNow Store enables customers to import and manage application vulnerabilities from Fortify products within ServiceNow's Vulnerability Response framework.
This integration supports prioritization and remediation of vulnerabilities across application versions, aligned with ServiceNow security and configuration best practices.
Show full answer Show less  

## Key Features and Enhancements

* **Version-specific vulnerability mapping:** From version 2.7.1 (September 2025), vulnerabilities are accurately assigned to specific application releases using both application and release IDs, preventing incorrect consolidation across versions.
* **Security and platform alignment:** Version 31.0.1 (June 2026) introduced table-level ACLs and field wildcards on import staging tables to comply with ServiceNow Platform Security guidance.
* **Configuration improvements:** Buffer time settings for imports were moved to instance parameters for easier management (version 2.4.2), and product model lookup rules supporting CSDM were added (version 2.1.0).
* **Workflow integration:** Manage exceptions and false positives directly within ServiceNow via triage workflows activated by default since version 2.2.1 (November 2023), streamlining vulnerability handling.
* **Operational enhancements:** Support for auto-closing application vulnerable items (version 2.3.3) and detailed reporting of integration run processing times (version 2.3.1) improve operational visibility and efficiency.
* **Remediation task management:** From version 2.2.2, remediation tasks for application vulnerabilities can be manually created from remediation task records, enhancing control over vulnerability remediation.

## Practical Considerations for Customers

* After upgrading to version 2.7.1 or later, a one-time cleanup and re-import of application and vulnerability data is required to ensure accurate version-specific mappings.
* Translation updates ensure newly activated locales pick up Fortify-specific translations automatically after upgrades, reducing administrative overhead.
* Security updates at the table and field level improve data protection and adhere to ServiceNow's security best practices.
* Customers benefit from integrated exception and false positive management workflows that facilitate vulnerability triage within the ServiceNow platform.
* System properties and instance parameters allow fine-tuning of import behaviors, such as buffer times and product model usage, supporting customization aligned with organizational needs.

## Expected Outcomes

ServiceNow customers using the Fortify Application Vulnerability Integration can expect improved accuracy in vulnerability tracking by application version, enhanced security compliance, streamlined vulnerability triage workflows, and greater operational control over import and remediation processes. These enhancements collectively support more effective vulnerability management and risk reduction within the ServiceNow Vulnerability Response ecosystem.  
Version history for the Fortify Application Vulnerability Integration on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## Version history

Version 31.0.1 - June 2026 (USEM)
:
    * The following enhancements and changes support internal security directives:
      * Query ACLs added at the table-level and field wildcard for the Fortify app-import staging table \[sn_vul_fortify_app_import\] to align with ServiceNow Platform Security guidance.
      * Preload and customization-detection fix scripts run exactly once per upgrade.
      * Translation packaging updated so newly activated locales automatically pick up Fortify-specific translations without requiring an instance repair.
      {#store-secops-rn-vr-fortify__ul_c1t_x5f_kjc}

Version 2.7.1 - September 2025
:
    * Fixed:
      * Resolved the incorrect consolidation of vulnerabilities across different application releases in the Fortify On-Demand Integration. Previously, vulnerabilities were assigned using only the application ID, ignoring the release ID, causing all versions of an application to show identical vulnerability data.
      * The integration now correctly uses both application ID and release ID to assign vulnerabilities to their specific application versions.
      * One-time cleanup needs to be performed for the AVITs from Fortify and re-run both the application list and vulnerability list integrations to ensure accurate version-specific vulnerability mapping.
      {#store-secops-rn-vr-fortify__ul_t4x_p4n_ngc}

Version 2.6.0 - May 2025
:   Fixes.{#store-secops-rn-vr-fortify__latest-store-secops-rn-vr-fortify}
{#store-secops-rn-vr-fortify__latest-store-secops-rn-vr-fortify}

Version 2.5.0 - November 2024
:   Minor fixes for this release.

Version 2.4.2 - August 2024
:   Changed: The \[sn_vul_fortify.buffer_hours\] property has been removed from system properties and added to the Fortify Vulnerability Integration instance parameters.

Version 2.3.3 - June 2024
:   New: Auto close for application vulnerable items is supported for the Fortify integrations.

Version 2.3.1 - May 2024
:   Changed: View details such as total processing times, average times for pre- and post-integration run processes, and reports on the integration run records.

Version 2.2.2 - February 2024
:
    * New:
      * You can reapply your configuration item (CI) lookup rules to update existing CIs (scanned applications and product models).
      * Manually create remediation tasks (AVULs) for application vulnerable items (AVITs) from remediation task records on the Group Configuration tab.
      {#store-secops-rn-vr-fortify__ul_hbr_gxv_21c}
    * Fixed: Buffer time is a configurable parameter with the sn_vul_veracode.import_starttime_buffer system property. The buffer, in hours, is subtracted from Start Time (delta_start_time). The scanner imports results at the new derived delta start time.

Version 2.2.1 - November 2023
:
    * New:
      * The manage exceptions in ServiceNow and manage false positives in ServiceNow options on the Fortify configuration page can help you triage your imported application vulnerabilities with ServiceNow workflows. These options are activated by default.
        * Manage exceptions in ServiceNow triages application vulnerable items (AVI) with the ServiceNow Exception management workflow. AVIs transition to Open, and you request exceptions from AVI records. Deactivate the option to preserve the Source states on AVIs imported from Fortify.
        * Manage false positives in ServiceNow triages false positives with the ServiceNow False positive workflow. AVIs transition to Open, and you request false positives from AVI records. Deactivate the option to preserve the Source states on AVIs imported from Fortify.
        {#store-secops-rn-vr-fortify__ul_f3j_y4g_2zb}
      {#store-secops-rn-vr-fortify__ul_tgj_y4g_2zb}

Version 2.1.0 - August 2023 (Vancouver)
:   New: New: A new product model lookup rule is activated by the system property, Use Product Model \[sn_vul.use_product_model\]. This rule supports CSDM.

Version 2.0.2 - March 2022
:   The Vulnerability Response integration with the Fortify on Demand product imports applications and application vulnerabilities to use with Application Vulnerability Response. Application Vulnerability Response is a
    feature in the ServiceNow Vulnerability Response application that helps you prioritize and remediate application vulnerabilities.

