Note:
This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.
If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the KB2556844 and documentation before proceeding.
If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
Vulnerability Response Integration with Veracode imports applications and application vulnerabilities using Application Vulnerability Response. Application Vulnerability Response is a feature in Vulnerability Response that helps you prioritize and remediate vulnerabilities.
Imports applications and application vulnerabilities resulting from Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), Software Composition Analysis (SCA), manual penetration testing results, and Software Bill of Materials (SBOM)s from Veracode into the Application Vulnerability Response feature. Some features of this integration:
- CI Lookup Rules - Lookup rules are used to search for configuration items (CIs) in the CMDB with matching information from the Veracode Vulnerability Integration.
- A shared API ingests DAST, SAST, SCA data and manual penetration testing results.
- A separate API is used to ingest SBOM data.
Fixed:
- An issue with the Veracode application vulnerable item (AVIT) ingestion that generated a large volume of 'undefined' warnings in logs whenever a finding's found/last-found/last-updated date was missing from an API response. By checking for missing date values before constructing a date/time object, and defaulting to an empty value instead of passing undefined values, date fields on imported findings are populated as expected.
- Large-scale, Veracode Link Projects and SBOM integrations that might generate between 5,000–10,000 Import Queue entries per run, because separate integration process, attachment, and Import Queue entries were created for every application. This process significantly slowed overall import completion for customers with large numbers of applications, because entries were processed one-at-a-time. By batching multiple application responses into a single integration process and preserving all existing downstream behaviors, the times for large Veracode imports are reduced without changing the imported data.
The following applications must be installed and activated:
- Vulnerability Response.
- ServiceNow Software Bill of Materials applications are required to view the data you import with the Veracode Software Bill of Materials (SBOM) Integration.
For information on Vulnerability Response application compatibility see, "Vulnerability Response and Configuration Compliance Compatibility Matrix" under Supporting Links and Docs.
Permissions and roles
- Role required: System Admin (admin) or Application Security Manager (User part of App-Sec Manager group)