Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
servicenow servicenow san diego vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-43684
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to P...
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Utah
Servicenow Servicenow Tokyo
1 Github repository
NA
CVE-2022-46389
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote malicious user to execute arbitrary JavaScript...
Servicenow Servicenow San Diego
Servicenow Servicenow Rome
Servicenow Servicenow Quebec
Servicenow Servicenow Utah
Servicenow Servicenow Tokyo
NA
CVE-2022-42704
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote malicious users to inject arbitrary web script via the Standard Ticket Conversations widget.
Servicenow Servicenow Quebec
Servicenow Servicenow Rome
Servicenow Servicenow San Diego
NA
CVE-2022-38463
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
Servicenow Servicenow San Diego
NA
CVE-2022-38172
ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.
Servicenow Servicenow San Diego
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started