ACL bypass in Reporting functionality
CVE-2022-43684
6.5MEDIUM
What is CVE-2022-43684?
An Access Control List (ACL) bypass vulnerability exists in ServiceNow's core functionality, affecting several releases. If exploited, this vulnerability allows authenticated users to access sensitive information from tables that lack proper authorization controls. The issue has been addressed through patches and upgrades provided by ServiceNow, targeting specific versions in the Quebec, Rome, San Diego, Tokyo, and Utah release series. It is crucial for organizations using these versions to apply the necessary updates to secure their data.
Affected Version(s)
Now Platform Quebec
Now Platform Rome
Now Platform San Diego
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Luke Symons
Tony Wu
Eldar Marcussen
Gareth Phillips
Jeff Thomas
Nadeem Salim
Stephen Bradshaw