ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.
Additional Details
This issue is present in the following supported ServiceNow releases:
* Quebec prior to Patch 10 Hot Fix 8b
* Rome prior to Patch 10 Hot Fix 1
* San Diego prior to Patch 7
* Tokyo prior to Tokyo Patch 1; and
* Utah prior to Utah General Availability
If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: SN
Published: 2023-06-13T18:51:39.984Z
Updated: 2024-08-03T13:40:06.227Z
Reserved: 2022-10-24T04:08:01.240Z
Link: CVE-2022-43684
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-13T19:15:09.243
Modified: 2024-11-21T07:27:02.167
Link: CVE-2022-43684
Redhat
No data.