ServiceNow Vulnerabilities and Affected Products
Vulnerabilities associated with Now Platform.
Products
Clear product- Now Platform11 vulnerabilities
- servicenow5 vulnerabilities
- ServiceNow AI Platform5 vulnerabilities
- Jenkins plug-in for ServiceNow DevOps2 vulnerabilities
- Utah, Vancouver, and Washington DC Now Platform2 vulnerabilities
- Now Assist AI Agents1 vulnerability
- Now User Experience1 vulnerability
- ServiceNow Records1 vulnerability
- Virtual Agent API1 vulnerability
- Washington DC, Vancouver, and Utah Now Platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3648HIGH | Data Inference in Now Platform via Conditional ACLsA vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query requests to infer instance data that is not intended to be accessible to them. To assist customers in enhancing access controls, ServiceNow has introduced additional access control frameworks in Xanadu and Yokohama, such… CWE-1220Jul 8, 2025 | CVSS8.2v4.0 | EPSS1.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0337HIGH | Authorization bypass in Now PlatformServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable an authenticated user to access unauthorized data stored within the Now Platform that the user otherwise would not be entitled to access. This issue is addressed in the listed patches and family release, which have been made available to hosted and self-hosted customers, as well as partners. CWE-639Mar 6, 2025 | CVSS7.1v4.0 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5890MEDIUM | HTML Injection in the Assessment pluginServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability could potentially enable an unauthenticated user to modify a web page or redirect users to another website. ServiceNow released updates to customers that addressed this vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible. CWE-79Dec 2, 2024 | CVSS5.1v4.0 | EPSS0.297% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8924HIGH | Unauthenticated Blind SQL Injection in Core PlatformServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes. CWE-89Oct 29, 2024 | CVSS8.7v4.0 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8923CRITICAL | Sandbox Escape in Now PlatformServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes. CWE-94Oct 29, 2024 | CVSS9.3v4.0 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5217CRITICAL | Incomplete Input Validation in GlideExpression ScriptServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as … | CVSS9.2v4.0 | EPSS99.6% | PoCs1 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-5178MEDIUM | Incomplete Input Validation in SecurelyAccess APIServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance… CWE-184Jul 10, 2024 | CVSS6.9v4.0 | EPSS33.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4879CRITICAL | Jelly Template Injection Vulnerability in ServiceNow UI MacrosServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recomme… | CVSS9.3v4.0 | EPSS>99.9% | PoCs10 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-43684CRITICAL | ACL bypass in Reporting functionalityServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it pot… | CVSS9.9v3.1 | EPSS1.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-46389MEDIUM | Cross-Site Scripting (XSS) vulnerability found on logout functionalityThere exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console. CWE-79Apr 17, 2023 | CVSS6.1v3.1 | EPSS0.595% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39048MEDIUM | Cross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirectA XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems. | CVSS6.1v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |