Snowpick: Open-source ServiceNow exposure scanner
ID: cb281a93-05b1-5389-b2bc-6d3d99c11559
STIX ID: report--cb281a93-05b1-5389-b2bc-6d3d99c11559
Feed Name: Help Net Security
Bishop Fox released Snowpick and a research write-up showing that misconfigurations in ServiceNow public surfaces (Service Portal widgets and the Table REST API) allowed unauthenticated sessions to retrieve or infer records from many instances — roughly 31% of 166 tested instances returned data or counts, exposing attachments, knowledge-base articles, ticket metadata, and other internal information. The issues are primarily access-control and configuration problems rather than new platform zero-days; the public release aims to accelerate remediation but also makes probing trivial for attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
