← Vulnerability feed

Vulnerability record · CVE-2022-43684 · published 13 June 2023

CVE-2022-43684: Servicenow information exposure vulnerability

Servicenow · Servicenow

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

6.5 CVSS 3.1 Medium EPSS 1.8% · top 22.4% CWE-200 · Information exposureCWE-668 · Exposure of resource to wrong sphere
6.5CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43684 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-4879ServiceNow Now Platform input validation flaw allows unauthenticated RCEServiceNow's Now Platform (Vancouver and Washington DC releases) contains an input validation vulnerability that lets an unauthenticated remote attac…KEVEPSS 100%analysed9.2CVE-2024-5217ServiceNow Now Platform input validation flaw enables unauthenticated RCEServiceNow's Washington DC, Vancouver, and earlier Now Platform releases contain an input validation vulnerability (CWE-184 incomplete list of disall…KEVEPSS 100%analysed9.3CVE-2024-8923Servicenow code injection vulnerabilityServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…EPSS 1.1%8.8CVE-2018-7748Servicenow code injection vulnerabilityreport_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…EPSS 2.6%8.7CVE-2024-8924Servicenow sql injection vulnerabilityServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthentica…EPSS 0.50%6.1CVE-2023-1298Servicenow cross-site scripting vulnerabilityServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow …EPSS 0.39%6.1CVE-2022-46389Servicenow cross-site scripting vulnerabilityThere exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, S…EPSS 0.60%6.1CVE-2022-46886Servicenow open redirect vulnerabilityThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2022-43684), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.