← Back to browse · API

CVE-2022-43684

Severity
CRITICAL
CVSS
9.9
EPSS
0.018
Risk score
40.23
CISA KEV
No
PoC
No
Published
2023-06-13
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2022-46677, GHSA-438X-9G8X-78P5
Products
Servicenow:Now Platform Quebec <Patch 10 Hot Fix 8b, Servicenow:Now Platform Rome <Patch 10 Hot Fix 1, Servicenow:Now Platform San Diego <Patch 7, Servicenow:Now Platform Tokyo <Tokyo Patch 1, Servicenow:Now Platform Utah <Utah General Availability (GA)
Sources
euvd EUVD-2022-46677

Description

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

References