There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Servicenow | Servicenow | quebec (including) | quebec (including) |
Servicenow | Servicenow | quebec-patch_10 (including) | quebec-patch_10 (including) |
Servicenow | Servicenow | rome-patch_1 (including) | rome-patch_1 (including) |
Servicenow | Servicenow | rome-patch_1_hotfix_1 (including) | rome-patch_1_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_1_hotfix_1b (including) | rome-patch_1_hotfix_1b (including) |
Servicenow | Servicenow | rome-patch_1_hotfix_2 (including) | rome-patch_1_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_1_hotfix_3 (including) | rome-patch_1_hotfix_3 (including) |
Servicenow | Servicenow | rome-patch_10 (including) | rome-patch_10 (including) |
Servicenow | Servicenow | rome-patch_10_hotfix_1 (including) | rome-patch_10_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_10_hotfix_2 (including) | rome-patch_10_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_10_hotfix_2a (including) | rome-patch_10_hotfix_2a (including) |
Servicenow | Servicenow | rome-patch_2 (including) | rome-patch_2 (including) |
Servicenow | Servicenow | rome-patch_2_hotfix_1 (including) | rome-patch_2_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_2_hotfix_2 (including) | rome-patch_2_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_3 (including) | rome-patch_3 (including) |
Servicenow | Servicenow | rome-patch_3_hotfix_1 (including) | rome-patch_3_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_4 (including) | rome-patch_4 (including) |
Servicenow | Servicenow | rome-patch_4_hotfix_1 (including) | rome-patch_4_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_4_hotfix_1a (including) | rome-patch_4_hotfix_1a (including) |
Servicenow | Servicenow | rome-patch_4_hotfix_1b (including) | rome-patch_4_hotfix_1b (including) |
Servicenow | Servicenow | rome-patch_5 (including) | rome-patch_5 (including) |
Servicenow | Servicenow | rome-patch_5_hotfix_1 (including) | rome-patch_5_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_5_hotfix_2 (including) | rome-patch_5_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_6 (including) | rome-patch_6 (including) |
Servicenow | Servicenow | rome-patch_6_hotfix_1 (including) | rome-patch_6_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_6_hotfix_2 (including) | rome-patch_6_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_7 (including) | rome-patch_7 (including) |
Servicenow | Servicenow | rome-patch_7_hotfix_1 (including) | rome-patch_7_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_7a (including) | rome-patch_7a (including) |
Servicenow | Servicenow | rome-patch_7b (including) | rome-patch_7b (including) |
Servicenow | Servicenow | rome-patch_8 (including) | rome-patch_8 (including) |
Servicenow | Servicenow | rome-patch_8_hotfix_1 (including) | rome-patch_8_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_8_hotfix_2 (including) | rome-patch_8_hotfix_2 (including) |
Servicenow | Servicenow | rome-patch_9 (including) | rome-patch_9 (including) |
Servicenow | Servicenow | rome-patch_9_hotfix_1 (including) | rome-patch_9_hotfix_1 (including) |
Servicenow | Servicenow | rome-patch_9a (including) | rome-patch_9a (including) |
Servicenow | Servicenow | rome-patch_9b (including) | rome-patch_9b (including) |
Servicenow | Servicenow | san_diego-patch_1 (including) | san_diego-patch_1 (including) |
Servicenow | Servicenow | san_diego-patch_1_hotfix_1 (including) | san_diego-patch_1_hotfix_1 (including) |
Servicenow | Servicenow | san_diego-patch_1_hotfix_1a (including) | san_diego-patch_1_hotfix_1a (including) |
Servicenow | Servicenow | san_diego-patch_1_hotfix_1b (including) | san_diego-patch_1_hotfix_1b (including) |
Servicenow | Servicenow | san_diego-patch_2 (including) | san_diego-patch_2 (including) |
Servicenow | Servicenow | san_diego-patch_2_hotfix_1 (including) | san_diego-patch_2_hotfix_1 (including) |
Servicenow | Servicenow | san_diego-patch_3 (including) | san_diego-patch_3 (including) |
Servicenow | Servicenow | san_diego-patch_3_hotfix_1 (including) | san_diego-patch_3_hotfix_1 (including) |
Servicenow | Servicenow | san_diego-patch_3_hotfix_2 (including) | san_diego-patch_3_hotfix_2 (including) |
Servicenow | Servicenow | san_diego-patch_3_hotfix_3 (including) | san_diego-patch_3_hotfix_3 (including) |
Servicenow | Servicenow | san_diego-patch_3_hotfix_4 (including) | san_diego-patch_3_hotfix_4 (including) |
Servicenow | Servicenow | san_diego-patch_4 (including) | san_diego-patch_4 (including) |
Servicenow | Servicenow | san_diego-patch_4a (including) | san_diego-patch_4a (including) |
Servicenow | Servicenow | san_diego-patch_4b (including) | san_diego-patch_4b (including) |
Servicenow | Servicenow | san_diego-patch_6 (including) | san_diego-patch_6 (including) |
Servicenow | Servicenow | san_diego-patch_7 (including) | san_diego-patch_7 (including) |
Servicenow | Servicenow | san_diego-patch_8 (including) | san_diego-patch_8 (including) |
Servicenow | Servicenow | tokyo (including) | tokyo (including) |
Servicenow | Servicenow | tokyo-patch1 (including) | tokyo-patch1 (including) |