Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2022-43684

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-200 Revelación de información
Fecha de publicación:
13/06/2023
Última modificación:
13/02/2025

Descripción

*** Pendiente de traducción *** ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.<br /> <br /> <br /> <br /> Additional Details<br /> <br /> This issue is present in the following supported ServiceNow releases: <br /> <br /> <br /> <br /> * Quebec prior to Patch 10 Hot Fix 8b<br /> * Rome prior to Patch 10 Hot Fix 1<br /> * San Diego prior to Patch 7<br /> * Tokyo prior to Tokyo Patch 1; and <br /> * Utah prior to Utah General Availability <br /> <br /> <br /> <br /> <br /> If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:servicenow:servicenow:quebec:patch_1_hotfix_1:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_10:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_10_hotfix_3:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_10_hotfix_3a:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_10_hotfix_3b:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_10_hotfix_4:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_2:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_2_hotfix_1:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_2_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_3:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_4:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_4_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_5:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_6:*:*:*:*:*:*
cpe:2.3:a:servicenow:servicenow:quebec:patch_7:*:*:*:*:*:*