CVE-2021-45901: Medium severity servicenow vulnerability
Published Feb 10, 2022
·Updated
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
Affected Software
7 affected components
ServiceNow ServiceNow=jakarta-p1
ServiceNow ServiceNow=jakarta-p2
ServiceNow ServiceNow=jakarta-p3
ServiceNow ServiceNow=jakarta-p3a
ServiceNow ServiceNow=jakarta-p3b
ServiceNow ServiceNow=jakarta-p4
ServiceNow ServiceNow=jakarta-p5
Event History
Feb 10, 2022
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45901.
2
What is the severity of CVE-2021-45901?
The severity of CVE-2021-45901 is medium with a severity value of 5.3.
3
What is the affected software for CVE-2021-45901?
The affected software for CVE-2021-45901 is ServiceNow Orlando with versions jakarta-p1, jakarta-p2, jakarta-p3, jakarta-p3a, jakarta-p3b, jakarta-p4, and jakarta-p5.
4
What is the description of CVE-2021-45901?
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
5
How can I fix CVE-2021-45901?
To fix CVE-2021-45901, upgrade ServiceNow Orlando to a patched version provided by the vendor.