Thousands of orgs at risk of knowledge base data leaks via ServiceNow misconfigurations
ID: ef035913-bcf6-51db-8556-a6a177d41946
STIX ID: report--ef035913-bcf6-51db-8556-a6a177d41946
Feed Name: The Register (Security)
Security researchers disclosed that ServiceNow Knowledge Base widgets can be misconfigured such that 'private' KB articles are retrievable by unauthenticated actors: the KB Article Page widget permits enumeration of predictable article IDs (KBXXXXXXX) and, with the g_ck JavaScript token, an attacker can POST requests to obtain full article content. Estimates suggest a large portion of ServiceNow instances (roughly 30–45%) were vulnerable; mitigations include applying proper User Criteria, ensuring relevant Business Rules are active, and following ServiceNow's guidance and proactive configuration fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
