Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
Summary
ServiceNow has released patches for four security vulnerabilities in its AI Platform. Three of these flaws are rated with a critical CVSS score of 10.0, allowing unauthenticated attackers to potentially execute code and perform SQL injection attacks under specific conditions.
IFF Assessment
The severity of these vulnerabilities, with three critical CVSS 10.0 ratings, indicates a significant threat to organizations using ServiceNow, as unauthenticated attackers could gain control and exfiltrate data.
Severity
The CVSS score of 10.0 indicates the highest level of severity, suggesting that these vulnerabilities are highly exploitable by unauthenticated attackers and have a critical impact, allowing for remote code execution and SQL injection.
Defender Context
Organizations utilizing ServiceNow's AI Platform should prioritize applying the released patches immediately. Defenders need to be aware of the potential for unauthenticated remote code execution and SQL injection, and monitor their ServiceNow instances for any signs of compromise.