ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
The vulnerability consists of improper input validation in the Now Platform. An attacker can submit a specially crafted network request without needing to possess an account or authentication credentials, and the platform improperly processes the supplied data, leading to arbitrary code execution in the context of the application. The vulnerability is remotely accessible over the network without any additional prerequisites.
An unauthenticated attacker can remotely execute arbitrary code in the context of the ServiceNow Now Platform, which may lead to system takeover, data disclosure, or data modification.
ServiceNow has deployed an update on all hosted instances automatically. Self-hosted customers and partners should immediately apply patches and hot fixes indicated by the vendor in KB1706070 article available in the ServiceNow support portal.
ServiceNow Now Platform — hosted instances and self-hosted environments of partners and customers in versions indicated in vendor references (KB1706070). ServiceNow has deployed the update on hosted instances and made it available to partners and self-hosted customers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XServicenow
APPServicenowvancouverwashington_dcxanadu
Related vulnerabilities
ServiceNow Now Platform — zdalny RCE bez uwierzytelnienia (input validation)
Krytyczna podatność RCE w ServiceNow Now Platform (input validation)
ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vul...
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...