Data Exposure Misconfiguration Issue in ServiceNow
ID: 606b2fcf-e22c-568b-8727-a081aca9e169
STIX ID: report--606b2fcf-e22c-568b-8727-a081aca9e169
Feed Name: Arctic Wolf Blog
Threat Score
On October 18, 2023 ServiceNow published guidance after AppOmni disclosed a misconfiguration in Access Control Lists (ACLs) where ACLs with no role, condition, or script combined with a public SimpleListWidget can allow unauthenticated actors to read specific tables and potentially exfiltrate sensitive data; ServiceNow provided detection and remediation steps (e.g., add gs.isLoggedIn() to ACL scripts) and additional hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
