Aqua Blog

Integrate Aqua and ServiceNow to Prioritize Vulnerabilities by Runtime Reality

Integrate Aqua and ServiceNow to Prioritize Vulnerabilities by Runtime Reality

TL;DR Most of the vulnerabilities in a container environment will never be exploited, the hard part is knowing which ones will. The remediation timeline for production workloads is not shrinking fast enough to keep up with attacks that adapt at machine speed, so teams cannot afford to work the list in severity order and hope. Aqua closes that gap by correlating code level vulnerability data with what is actually running in production, so teams can see which risks matter right now and use that to inform policy, enforcement and workload control. Aqua’s integration with ServiceNow puts that same correlated, prioritized view directly into the Vulnerability Response module, so triage and remediation run on runtime reality instead of a raw list of CVEs.

What does the Aqua integration with ServiceNow do?

A severity score tells you how bad a vulnerability could be, not whether it is a risk to your business right now. Containers enable rapid DevOps releases and rely heavily on open source components. That same scale and agility create an endless stream of known vulnerabilities, many of which exist only in images that never run. Meanwhile the timeline to actually remediate a production workload is not shrinking, and attackers that adapt at machine speed do not wait for a patch cycle to catch up. Without a way to tell which vulnerabilities are real risk right now, teams are left working in severity order instead of by what is actually exploitable.

This is the problem Aqua solves before ServiceNow ever sees a finding. Aqua correlates code level vulnerability data with what is actually running in production. This runtime context helps teams prioritize the vulnerabilities that pose real risk and enforce controls directly within affected workloads. The ServiceNow integration takes that same prioritized, runtime informed view and delivers it into ServiceNow’s Vulnerability Response module, so triage and remediation start from what Aqua has already determined matters, not from a raw CVE count.

How does it work?

Aqua’s container security scanning covers images in the registry and workloads running in production, checking for vulnerabilities, secrets and malware across the base images and Dockerfiles that make up a container. The Aqua Security app, installed from the ServiceNow Store, connects that scanning to ServiceNow’s Vulnerability Response module. An admin configures the connection under Aqua Security, Configuration, using either a username and password or an API key and secret, along with the Aqua server URL.

Filters decide what actually reaches ServiceNow: whether to include only images tied to running workloads, which severities to pull and whether to include vulnerabilities without a known exploit or vendor fix. The running workload filter brings Aqua’s runtime context into ServiceNow by distinguishing vulnerabilities in unused images from those in workloads that are actively deployed and reachable. The integration creates three scheduled jobs for images, vulnerabilities and application scopes. Each job can run on demand or on a recurring schedule. Turning on Use Aqua Auto Close keeps ServiceNow’s records current as Aqua resolves findings.

Inside ServiceNow, that data lands in three places:

  1. Container Vulnerable Items include the CVE ID, severity, and score for each vulnerability, and the same records are visible on ServiceNow’s Third Party Vulnerability Entries screen.
  2. Discovered Container Images include the image SHA ID, repository, and Docker labels for every image where a vulnerability was found, and mirror them in the Container Image Packages screen.
  3. Container Image Findings record each instance of a vulnerability, so a team can see not just that a CVE exists but everywhere it actually shows up.

What does this mean for Aqua customers?

Aqua prioritizes vulnerabilities based on runtime reality, not severity alone. A critical CVE in an unused image does not pose the same risk as the same CVE in a workload serving production traffic. The running workload filter gives ServiceNow the context to distinguish between them.

The runtime context that informs Aqua’s enforcement also flows directly into ServiceNow. Aqua uses this intelligence to determine which risks require control within the workload, then sends that same prioritized view to the Vulnerability Response module. As a result, ServiceNow triage reflects what Aqua has already identified as meaningful production risk.

Application scopes help organize ownership and assignment at scale. Detailed findings show remediation teams exactly which image and workload instance require attention, rather than simply indicating that a vulnerability exists somewhere in the environment.

Where does this matter most?

  • Vulnerability management at scale. When findings exceed what teams can review manually, runtime correlation makes the backlog manageable by showing which vulnerabilities are present in workloads running in production.
  • Zero day response. When a zero day emerges, teams need to identify exposed production workloads quickly. Runtime context shows where the vulnerability is actively running without requiring teams to rescan the entire environment from scratch.
  • Compliance and audit reporting. Container Vulnerable Items, Discovered Container Images and Container Image Findings sync on a recurring schedule. This keeps compliance reporting aligned with Aqua’s current, runtime informed view rather than a static export.

What do you need to get started?

The integration requires ServiceNow admin access to install the Aqua Security app and the necessary plugins for Vulnerability Response and Configuration Compliance. Aqua credentials are also required to complete the connection using either basic authorization or an API key and secret.

Customers can follow Aqua’s ServiceNow integration guide on Aqua Docs (login required) to configure the integration, or request a demo to see it in action.

FAQ
What ServiceNow screens does Aqua data appear in?

Container Vulnerable Items, Discovered Container Images and Container Image Findings, with the same data mirrored into ServiceNow’s Third Party Vulnerability Entries and Container Image Packages screens.

How does Aqua decide what counts as high priority?

By combining severity, exploit availability and vendor fix status with whether the image is tied to a running workload, so priority reflects real exposure, not just a CVE score.

Will old vulnerability data pile up in ServiceNow?

Not if Use Aqua Auto Close is enabled. Vulnerabilities Aqua no longer detects are closed automatically instead of remaining as open, outdated items.

Do I need a separate configuration for every Aqua environment?

No, the sub account setup lets a single ServiceNow instance stay mapped correctly across more than one Aqua environment.

Aqua Team
Aqua Security is the pioneer in securing containerized cloud native applications from development to production. The Aqua full lifecycle solution prevents attacks by enforcing pre-deployment hygiene and mitigates attacks in real time in production, reducing mean time to repair and overall business risk. The Aqua Platform, a Cloud Native Application Protection Platform (CNAPP), integrates security from Code to Cloud, combining the power of agent and agentless technology into a single solution. With enterprise scale that doesn’t slow development pipelines, Aqua secures your future in the cloud. Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL protecting over 500 of the world’s largest enterprises.