ServiceNow has issued an urgent advisory regarding three critical security vulnerabilities affecting its platform. These flaws, identified as CVE-2024-4835, CVE-2024-4836, and CVE-2024-4839, could allow unauthenticated attackers to execute remote code or gain unauthorized access to sensitive data. The vulnerabilities involve improper input validation and cross-site scripting (XSS) within the platform's core components.
Organizations using ServiceNow are strongly advised to apply the latest patches immediately. Security researchers have noted that these vulnerabilities are particularly dangerous because they can be exploited without prior authentication, potentially compromising enterprise workflows and internal data management systems. ServiceNow has released updates for various versions, including Vancouver and Washington D.C., to mitigate these risks.
Top comments (0)