CVE-2022-38172: XSS
Published Aug 23, 2022
·Updated
ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.
Affected Software
7 affected components
ServiceNow ServiceNow=san_diego-patch_1
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1a
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1b
ServiceNow ServiceNow=san_diego-patch_2
ServiceNow ServiceNow=san_diego-patch_2_hotfix_1
ServiceNow ServiceNow=san_diego-patch_3
Event History
Aug 23, 2022
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this ServiceNow vulnerability?
The vulnerability ID for this ServiceNow vulnerability is CVE-2022-38172.
2
What is the severity of CVE-2022-38172?
The severity of CVE-2022-38172 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2022-38172?
The affected software for CVE-2022-38172 is ServiceNow through San Diego Patch 3.
4
How does CVE-2022-38172 allow XSS attacks?
CVE-2022-38172 allows XSS attacks through the name field during creation of a new dashboard for the Performance Analytics dashboard in ServiceNow.
5
How can I fix CVE-2022-38172?
To fix CVE-2022-38172, apply the necessary patch provided by ServiceNow and follow their recommended mitigation steps.