DEV Community

Cover image for Critical ServiceNow AI Platform Vulnerabilities Allow Unauthenticated Data Access
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Critical ServiceNow AI Platform Vulnerabilities Allow Unauthenticated Data Access

Summary

ServiceNow patched five vulnerabilities in its AI Platform, including two critical flaws that allow unauthenticated attackers to execute SQL commands and extract sensitive instance data. These vulnerabilities affect self-hosted instances and could lead to full data compromise or privilege escalation.

Take Action:

If you run self-hosted ServiceNow (Yokohama, Zurich or Australia releases), update now to the fixed versions ASAP. If you can't patch today, restrict access to your instance to trusted IP addresses only. If you're on ServiceNow cloud in the August Patching Program, you're already covered.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)