logo

Data Exposure Misconfiguration Issue in ServiceNow

ID: 606b2fcf-e22c-568b-8727-a081aca9e169

STIX ID: report--606b2fcf-e22c-568b-8727-a081aca9e169

Feed Name: Arctic Wolf Blog

Threat Score
60/100

Date Published: 2023-10-23

Date Updated: 2026-04-27

...
...

On October 18, 2023 ServiceNow published guidance after AppOmni disclosed a misconfiguration in Access Control Lists (ACLs) where ACLs with no role, condition, or script combined with a public SimpleListWidget can allow unauthenticated actors to read specific tables and potentially exfiltrate sensitive data; ServiceNow provided detection and remediation steps (e.g., add gs.isLoggedIn() to ACL scripts) and additional hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.