Record summary

CVE-2022-46389 has a selected CVSS score of 6.1 (medium).

Description

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListQuebec to < Patch 10 Hotfix 11baffected
Rome to < Patch 10 Hotfix 3baffected
San Diego to < Patch 9affected
Tokyo to < Patch 4affected
Utah to < GAaffected

References

2