Skip to main content

Vendor archive

servicenow CVEs

Beta · best-effort

18 CVEs tagged to vendor servicenow5 Critical, 2 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2024-8924

Published Oct 29, 2024

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthoriz…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8923

Published Oct 29, 2024

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute cod…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5217

Published Jul 10, 2024

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-4879

Published Jul 10, 2024

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentic…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-1298

Published Jul 6, 2023

ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerabi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43684

Published Jun 13, 2023

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is presen…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-1209

Published May 23, 2023

Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46389

Published Apr 17, 2023

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46886

Published Apr 14, 2023

There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL with…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39048

Published Apr 10, 2023

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42704

Published Jan 13, 2023

A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arb…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38463

Published Aug 23, 2022

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38172

Published Aug 23, 2022

ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45901

Published Feb 10, 2022

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20768

Published May 5, 2020

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameter…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7748

Published Aug 3, 2018

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media pa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8720

Published Mar 15, 2018

ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka search_results.do).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1