Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Summary

ServiceNow has released patches for four security vulnerabilities in its AI Platform. Three of these flaws are rated with a critical CVSS score of 10.0, allowing unauthenticated attackers to potentially execute code and perform SQL injection attacks under specific conditions.

IFF Assessment

FOE

The severity of these vulnerabilities, with three critical CVSS 10.0 ratings, indicates a significant threat to organizations using ServiceNow, as unauthenticated attackers could gain control and exfiltrate data.

Severity

10.0 Critical

The CVSS score of 10.0 indicates the highest level of severity, suggesting that these vulnerabilities are highly exploitable by unauthenticated attackers and have a critical impact, allowing for remote code execution and SQL injection.

Defender Context

Organizations utilizing ServiceNow's AI Platform should prioritize applying the released patches immediately. Defenders need to be aware of the potential for unauthenticated remote code execution and SQL injection, and monitor their ServiceNow instances for any signs of compromise.

Read Full Story →