5.3
CVSSv3

CVE-2021-45901

Published: 10/02/2022 Updated: 22/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

servicenow servicenow jakarta

Exploits

ServiceNow Orlando suffers from a username enumeration vulnerability ...

Github Repositories

CVE-2021-45901 (ServiceNow - Username Enumeration) PoC Code enumSNOWUserspy - SNOW User Enumerator Title Username Enumeration Vulnerability found in ServiceNow Application Published: Version: 10 Vendor: ServiceNow Product: ServiceNow (wwwservicenowcom/) Version affected: Orlando (glide-orlando-12-11-2019__patch5-06-17-2020) Product description: ServiceNow is an A