Description
ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configuration. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before Washington DC Patch 10 Hot Fix 7b
Any version before Xanadu Patch 10 Hot Fix 1a
Any version before Xanadu Patch 11
Any version before Yokohama Patch 7 Hot Fix 2a
Any version before Yokohama Patch 8
Any version before Yokohama Patch 9
Any version before Zurich Patch 1 Hot Fix 1a
Any version before Zurich Patch 2
Any version before Zurich Patch 3
Any version before Australia General Availability (GA)
Credits
Adam Kues - Assetnote
Shubham Shah - Assetnote
References
support.servicenow.com/...cle_view&sysparm_article=KB2552817