Vulnerabilidades em ServiceNow
26 resultadosAnálise Vexday
ServiceNow apresenta 21 vulnerabilidades conhecidas em sua base, com 2 atualmente sob ataque ativo e 7 classificadas como críticas, indicando risco moderado a elevado. A fraqueza dominante é CWE-79 (cross-site scripting), pattern recorrente que sugere lacunas na validação de entrada. Com apenas 1 CVE publicada nos últimos 90 dias, o risco parece estabilizado, mas as 2 vulnerabilidades em exploração ativa demandam priorização imediata de patches.
CVE-2025-11450MEDIUMReflected Cross Site Scripting in ServiceNow AI PlatformEPSS 0.4%CVE-2025-3089MEDIUMBroken Access Control in ServiceNow AI PlatformEPSS 0.4%CVE-2024-5890MEDIUMHTML Injection in the Assessment pluginEPSS 0.3%CVE-2022-46886MEDIUMThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrEPSS 0.3%CVE-2026-74820CRITICALUnauthenticated SQL Injection via Dynamic Schema ORDER BY ClauseEPSS 0.2%CVE-2026-18886CRITICALUnauthenticated Privilege Escalation via System Configuration Image Upload ProcessorEPSS 0.2%