Skip to main content
Back to Newswire
Security

ServiceNow issues patches for three CVSS 10 code-injection flaws

ServiceNow issues patches for three CVSS 10 code-injection flaws Image: Primary
ServiceNow said it has deployed patches across hosted instances and released hotfixes for self-hosted deployments after disclosure of four vulnerabilities in its AI platform and Now Platform. Three flaws, rated CVSS 10, allow code execution, arbitrary data changes or arbitrary SQL statements in low-complexity attacks without authentication or user interaction. A fourth, rated 8.7, is a sandbox-escape issue that can enable code execution. The self-hosted hotfixes cover the Xanadu, Yokohama, Zurich and Australia releases.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire