CVE-2022-38463: XSS
Published Aug 23, 2022
·Updated
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
Affected Software
3 affected components
ServiceNow ServiceNow=san_diego-patch_4
ServiceNow ServiceNow=san_diego-patch_4a
ServiceNow ServiceNow=san_diego-patch_6
Event History
Aug 23, 2022
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38463?
CVE-2022-38463 is a vulnerability in ServiceNow through San Diego Patch 4b and Patch 6 that allows reflected XSS in the logout functionality.
2
How severe is CVE-2022-38463?
CVE-2022-38463 has a severity rating of 6.1, which is considered medium.
3
What software versions are affected by CVE-2022-38463?
CVE-2022-38463 affects ServiceNow San Diego Patch 4, Patch 4a, and Patch 6.
4
How can I fix CVE-2022-38463?
To fix CVE-2022-38463, update ServiceNow to a version that includes a patch for this vulnerability.
5
Where can I find more information about CVE-2022-38463?
You can find more information about CVE-2022-38463 in the ServiceNow knowledge base article: [link](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1156793).