Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
servicenow servicenow quebec vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-43684
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to P...
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Utah
Servicenow Servicenow Tokyo
1 Github repository
NA
CVE-2022-46389
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote malicious user to execute arbitrary JavaScript...
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Utah
Servicenow Servicenow Tokyo
NA
CVE-2022-46886
There exists an open redirect within the response list update functionality of ServiceNow. This allows malicious users to redirect users to arbitrary domains when clicking on a URL within a service-now domain.
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Tokyo
NA
CVE-2022-39048
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various clien...
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Utah
Servicenow Servicenow Tokyo
NA
CVE-2022-42704
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote malicious users to inject arbitrary web script via the Standard Ticket Conversations widget.
Servicenow Servicenow Quebec
Servicenow Servicenow Rome
Servicenow Servicenow San Diego
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started