logo

NJP

Vulnerability Exposure Assessment

Vulnerability Exposure Assessment

by Service-now.com

Integrate with Vulnerability Emergency Response to address zero-day or critical vulnerabilities

0 installs 0 reviews v30.6.3 Scoped Application Free-ish (consumes 13 tables) 13 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 88 -88
143 days of no change
2025-12-04 87 +1
5 days of no change
2025-11-28 86 +1
2 days of no change
2025-11-25 85 +1
13 days of no change
2025-11-11 84 +1
14 days of no change
2025-10-27 83 +1
24 days of no change
2025-10-02 82 +1
2 days of no change
2025-09-29 81 +1
2025-09-28 80 +1
5 days of no change
2025-09-22 79 +1
6 days of no change
2025-09-15 78 +1
16 days of no change
2025-08-29 77 +1
10 days of no change
2025-08-18 76 +1
21 days of no change
2025-07-27 75 +1
12 days of no change
2025-07-14 74 +1
3 days of no change
2025-07-10 72 +2
3 days of no change
2025-07-06 71 +1
12 days of no change
2025-06-23 70 +1
13 days of no change
2025-06-09 69 +1
6 days of no change
2025-06-02 68 +1
12 days of no change
2025-05-20 67 +1
25 days of no change
2025-04-24 66 +1
14 days of no change
2025-04-09 65 +1
1 days of no change
2025-04-07 62 +3
2 days of no change
2025-04-04 61 +1
3 days of no change
2025-03-31 60 +1
4 days of no change
2025-03-26 59 +1
2 days of no change
2025-03-23 58 +1
19 days of no change
2025-03-03 57 +1
13 days of no change
2025-02-17 56 +1
12 days of no change
2025-02-04 55 +1
17 days of no change
2025-01-17 53 +2
14 days of no change
2025-01-02 52 +1
63 days of no change
2024-10-30 46 +6

About

**Note:**

**This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.**

**If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the [KB2556844](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2556844) and [documentation](https://www.servicenow.com/docs/r/security-management/unified-security-exposure-management-landing-page.html) before proceeding.**

**If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.**

Vulnerability Emergency Response is a comprehensive solution for proactive vulnerability management and crisis response. In a single workspace, it offers, standalone assessments for a single CVE and vulnerable product versions, while the newly introduced Vulnerability Crisis Management Workflow enables you to efficiently handle vulnerability crisis events from end-to-end. This workflow includes holistic exposure assessment to identify vulnerable Configuration Items, vulnerable item creation, and crisis declaration with major security incident management enabling cross-team engagement, collaboration, coordination and reporting for rapid response.

Key Features

- Vulnerability Assessment Workspace for Vulnerability Event Managers to proactively manage critical vulnerabilities.
- Exposure Assessment
- Assess organization exposure for a single CVE or vulnerable product version.
- Accurate assessments with the normalized inventory of Software Asset Management.
- Automatic assessments of CISA, KEV, CVEs or CPEs

- Vulnerability Crisis Management - A complete workflow to handle vulnerability crisis events with the following capabilities.
- Efficiently identify vulnerable CIs by correlating critical vulnerabilities with software installations inventory (SAM), Software Bill of Materials Inventory (SBOM), scanner-reported vulnerabilities and CMDB.
- Generate vulnerable items for remediation based on assessment results, streamlining the remediation process.
- Initiate a major security incident response, ensuring swift and coordinated action.
- Engage and collaborate with teams across the organization, facilitating a unified response to vulnerabilities.
- Provide regular status reports to affected teams, partner teams, and leadership, maintaining transparency throughout the crisis.

Version History (15)
v30.6.3 2026-08-07 18:58:20
Fixed: CVE severity selection to the Exposure Assessment modal on Assess by Publisher tab. Updated the Vulnerability Assessment Configuration Item...
v30.6.0 2026-06-16 16:46:50
Changed: The vulnerability exposure assessment workflow now excludes inactive component dependencies from analysis. Application Vulnerable Items ...
v30.4.0 2026-04-09 15:34:02
Changed CI filtering for vulnerability assessments: You can now filter which configuration items are included in a vulnerability assessment using ...
v30.2.1 2026-01-20 15:00:19
Minor defect fix as part of this release, related to the functionality of adding a new affected product in Vulnerability Assessment Workspace
v30.1.1 2025-12-11 14:55:56
Changed: Adopted modularized calculator for vulnerability assessments.
v5.5.4 2026-08-07 19:00:58
Fixed: CVE severity selection to the Exposure Assessment modal on Assess by Publisher tab. Updated the Vulnerability Assessment Configuration Item...
v5.5.2 2026-06-16 16:46:43
Fixed: An issue where null related records might trigger unnecessary full table scans when vulnerable items (VITs) and application vulnerable items...
v5.5.0 2026-04-09 15:30:33
New: CI Filter on Vulnerability Assessment With a new ci_filter conditions field scoped to cmdb_ci that has been added to sn_vul_analyst_vuln...
v5.3.0 2026-01-20 14:58:11
Performance enhancements in Exposure Assessment scheduled job
v5.2.3 2025-12-11 14:52:53
Fixed  PRB1926442: [Security Bug] ACL Bypass via 'sn_vul_analyst.Activate CVE' Data Broker Removed sn_vul_analyst.emergency_response r...

+ 5 more versions

ID: 9a8a59054a76a1101c45d89ce7b2e7c9 · Published: Aug 2026 · Updated: Sep 09, 2026