Critical ServiceNow Vulnerabilities (CVSS 10.0) Enable Unauthenticated Code and SQL Execution
ServiceNow disclosed three CVSS 10.0 vulnerabilities enabling unauthenticated code execution and SQL injection through its AI platform, with patches released for affected versions. The flaws impact confidentiality, integrity, and availability, affecting multiple platform versions including Xanadu, Yokohama, Zurich, and Australia.
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.
The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
*** END OF TRANSMISSION ***