ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow has released patches for three critical code injection vulnerabilities, affecting customers using its Now Platform, Now Platform Flex, and Now Platform Enterprise.

Bottom line: ServiceNow customers must apply the patches to prevent exploitation by attackers who could execute arbitrary code and access or tamper with data.

What's happening: The vulnerabilities, tracked as CVE-2022-22463, CVE-2022-22464, and CVE-2022-22465, affect Now Platform, Now Platform Flex, and Now Platform Enterprise versions 10.10.0 and earlier. Attackers could potentially exploit these vulnerabilities in the US, UK, and Australia, between September 1, 2022, and March 15, 2023.

What to do: Security leaders must apply the patches to affected Now Platform, Now Platform Flex, and Now Platform Enterprise instances, and ensure all users are updated to the latest version, 10.10.1 or later, to prevent exploitation.

Source: SecurityWeek