Akamai integrates with ServiceNow Application Vulnerability Response (AVR), providing security teams with a centralized hub to discover, track, and remediate API vulnerabilities across the entire lifecycle.
By continuously evaluating API configurations and behaviors, Akamai identifies complex security risks and maps them directly into the ServiceNow AVR environment. This ensures that API risks are treated with the same rigor as traditional application vulnerabilities, enabling seamless cross-team collaboration and faster time-to-remediation.
-
Enhances the ServiceNow vulnerability catalog with specialized API-related findings and security policies.
-
Automates the association of AVIs to CIs using customizable lookup rules based on API-specific metadata.
-
Real-time updates for AVIs statuses and comments. Actions taken in either ServiceNow or Akamai API Security stay perfectly in sync.
Akamai API Security Integration for AVR — Version 1.4.2
What’s New Clearer errors when ServiceNow permissions are missing
Before the Get Findings job runs, AVR now validates that the required ServiceNow roles are assigned.
If a required role is missing, the sync log displays a descriptive message identifying the user and the missing role, for example:
VR.System User Missing Required Roles: "<role name>"
This replaces silent sync failures that previously required manual troubleshooting.
Reporting access on AVR tables
report_view access control is now defined for all custom AVR tables and aligned with the existing read permissions.
Users who have read access to a table can now also build reports based on that table.
Updated documentation link
The documentation link on the AVR Configuration page has been updated to point to the current AVR documentation.
Fixes
- Sensitive configuration values, including client secrets, are now masked in AVR logs.
- The First Found field on Akamai vulnerable items is now populated using the Akamai detection time.
- Akamai severity mappings are now applied to Akamai vulnerable item tasks, ensuring severity is normalized as expected.
Upgrade Note
Access control on AVR data tables no longer grants automatic access to ServiceNow platform administrators.
Access to AVR data tables now requires one of the following AVR roles:
- x_noga_noname_vr.admin
- x_noga_noname_vr.user
Before upgrading, confirm that all users and service accounts that require access to AVR tables have one of these roles assigned.
-
ServiceNow Application: Application Vulnerability Response (AVR).