CVE-2018-7748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
03/08/2018
Last modified:
05/10/2018

Description

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:servicenow:servicenow:jakarta:*:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p2:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p3:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p3a:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p3b:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p4:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p5:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p6:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p6a:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p7:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:jakarta:p8:*:*:*:*:*:*