CVE-2022-43684: ACL bypass in Reporting functionality
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.
Additional Details
This issue is present in the following supported ServiceNow releases:
Quebec prior to Patch 10 Hot Fix 8b Rome prior to Patch 10 Hot Fix 1 San Diego prior to Patch 7 Tokyo prior to Tokyo Patch 1; and Utah prior to Utah General Availability
If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43684?
CVE-2022-43684 is considered a high severity vulnerability due to its potential for unauthorized access through an ACL bypass.
How do I fix CVE-2022-43684?
To fix CVE-2022-43684, apply the latest patches provided by ServiceNow for the affected Quebec and Rome releases.
Which versions of ServiceNow are impacted by CVE-2022-43684?
CVE-2022-43684 affects ServiceNow Quebec prior to Patch 10 Hot Fix 8b and various versions of Rome prior to their respective patches.
What type of vulnerability is CVE-2022-43684?
CVE-2022-43684 is an Access Control List (ACL) bypass vulnerability that could allow unauthorized access to sensitive information.
Who released patches for CVE-2022-43684?
Patches for CVE-2022-43684 were released by ServiceNow to address the identified vulnerability in their core functionality.