ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XServicenow
APPServicenowvancouverwashington_dcxanadu
Related vulnerabilities
Krytyczna podatność RCE w ServiceNow Now Platform (input validation)
ServiceNow Now Platform — zdalny RCE bez uwierzytelnienia (input validation)
Zdalne wykonanie kodu w ServiceNow Now Platform (RCE bez uwierzytelnienia)
ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...