Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
The Hacker News
Read full postServiceNow patched four security vulnerabilities in its AI Platform, including three critical CVSS 10.0 flaws that allow unauthenticated attackers to execute code and perform SQL injection. The updates were deployed to hosted instances, while self-hosted customers must apply fixes manually. These vulnerabilities pose severe risks due to their ease of exploitation and high impact on system confidentiality, integrity, and availability.




