CVE Database
/

CVE-2022-46886

Back to search

CVE-2022-46886

Published: Apr 14, 2023

Modified: Feb 6, 2025

PUBLISHED

CVSS v3.1

5.5

MEDIUM

Description

There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.

VendorProductVersions

ServiceNow

ServiceNow

affected
Tokyo - < Tokyo Patch 1b
affected
San Diego - < San Diego Patch 7b
affected
Rome - < Rome Patch 10 Hotfix 2b
affected
Quebec - < Quebec Patch 10 Hotfix 10b

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now