CVE-2023-1209: XSS
Published May 23, 2023
·Updated
Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.
Affected Software
77 affected components
ServiceNow ServiceNow=rome
ServiceNow ServiceNow=rome-patch_1
ServiceNow ServiceNow=rome-patch_1_hotfix_1
ServiceNow ServiceNow=rome-patch_1_hotfix_1a
ServiceNow ServiceNow=rome-patch_1_hotfix_1b
ServiceNow ServiceNow=rome-patch_1_hotfix_2
ServiceNow ServiceNow=rome-patch_10
ServiceNow ServiceNow=rome-patch_10_hotfix_1
ServiceNow ServiceNow=rome-patch_10_hotfix_2
ServiceNow ServiceNow=rome-patch_10_hotfix_2a
ServiceNow ServiceNow=rome-patch_10_hotfix_2b
ServiceNow ServiceNow=rome-patch_10_hotfix_3b
ServiceNow ServiceNow=rome-patch_2
ServiceNow ServiceNow=rome-patch_3
ServiceNow ServiceNow=rome-patch_3_hotfix_1
ServiceNow ServiceNow=rome-patch_4
ServiceNow ServiceNow=rome-patch_4_hotfix_1
ServiceNow ServiceNow=rome-patch_4_hotfix_1a
ServiceNow ServiceNow=rome-patch_4_hotfix_1b
ServiceNow ServiceNow=rome-patch_5
ServiceNow ServiceNow=rome-patch_5_hotfix_1
ServiceNow ServiceNow=rome-patch_5_hotfix_2
ServiceNow ServiceNow=rome-patch_6
ServiceNow ServiceNow=rome-patch_6_hotfix_1
ServiceNow ServiceNow=rome-patch_6_hotfix_2
ServiceNow ServiceNow=rome-patch_7_hotfix_1
ServiceNow ServiceNow=rome-patch_7a
ServiceNow ServiceNow=rome-patch_7b
ServiceNow ServiceNow=rome-patch_8
ServiceNow ServiceNow=rome-patch_8_hotfix_1
ServiceNow ServiceNow=rome-patch_8_hotfix_2
ServiceNow ServiceNow=rome-patch_9
ServiceNow ServiceNow=rome-patch_9_hotfix_1
ServiceNow ServiceNow=rome-patch_9a
ServiceNow ServiceNow=rome-patch_9b
ServiceNow ServiceNow=san_diego
ServiceNow ServiceNow=san_diego-patch_1
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1a
ServiceNow ServiceNow=san_diego-patch_1_hotfix_1b
ServiceNow ServiceNow=san_diego-patch_2
ServiceNow ServiceNow=san_diego-patch_2_hotfix_1
ServiceNow ServiceNow=san_diego-patch_3
ServiceNow ServiceNow=san_diego-patch_3_hotfix_1
ServiceNow ServiceNow=san_diego-patch_3_hotfix_2
ServiceNow ServiceNow=san_diego-patch_3_hotfix_3
ServiceNow ServiceNow=san_diego-patch_3_hotfix_4
ServiceNow ServiceNow=san_diego-patch_4
ServiceNow ServiceNow=san_diego-patch_4a
ServiceNow ServiceNow=san_diego-patch_6
ServiceNow ServiceNow=san_diego-patch_7
ServiceNow ServiceNow=san_diego-patch_7_hotfix_1
ServiceNow ServiceNow=san_diego-patch_7_hotfix_2
ServiceNow ServiceNow=san_diego-patch_7_hottix_3
ServiceNow ServiceNow=san_diego-patch_7a
ServiceNow ServiceNow=san_diego-patch_7b
ServiceNow ServiceNow=san_diego-patch_8
ServiceNow ServiceNow=san_diego-patch_8_hotfix_1
ServiceNow ServiceNow=san_diego-patch_8_hotfix_2
ServiceNow ServiceNow=san_diego-patch_9
ServiceNow ServiceNow=tokyo
ServiceNow ServiceNow=tokyo-patch_1
ServiceNow ServiceNow=tokyo-patch_1_hotfix_1
ServiceNow ServiceNow=tokyo-patch_1a
ServiceNow ServiceNow=tokyo-patch_1b
ServiceNow ServiceNow=tokyo-patch_2
ServiceNow ServiceNow=tokyo-patch_2_hotfix_1
ServiceNow ServiceNow=tokyo-patch_2_hotfix_2
ServiceNow ServiceNow=tokyo-patch_2_hotfix_3
ServiceNow ServiceNow=tokyo-patch_2_hotfix_4
ServiceNow ServiceNow=tokyo-patch_3
ServiceNow ServiceNow=tokyo-patch_3_hotfix_1
ServiceNow ServiceNow=tokyo-patch_3_hotfix_2
ServiceNow ServiceNow=tokyo-patch_3_hotfix_3
ServiceNow ServiceNow=tokyo-patch_3_hotfix_4
ServiceNow ServiceNow=tokyo-patch_4
ServiceNow ServiceNow=utah
Event History
May 23, 2023
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1209?
CVE-2023-1209 is classified as a medium severity vulnerability due to the potential for authenticated attackers to exploit XSS vulnerabilities.
2
How do I fix CVE-2023-1209?
To fix CVE-2023-1209, update to the latest patched version of ServiceNow, as recommended in the security advisories.
3
Which ServiceNow versions are affected by CVE-2023-1209?
CVE-2023-1209 affects multiple versions of ServiceNow, including Rome, San Diego, and Tokyo releases.
4
What type of vulnerability is CVE-2023-1209?
CVE-2023-1209 is a Cross-Site Scripting (XSS) vulnerability that allows injection of arbitrary scripts.
5
Can CVE-2023-1209 be exploited remotely?
CVE-2023-1209 requires authentication, meaning that an attacker must have valid credentials to exploit the vulnerability.