ServiceNow AI Platform是美国ServiceNow公司的一款AI智能平台。 ServiceNow AI Platform存在安全漏洞,该漏洞源于SQL注入,可能导致未经身份验证的用户在特定情况下对底层数据库执行任意SQL语句,并访问或修改实例数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | < Xanadu Patch 11 Hot Fix 7a |
affected |
< Yokohama Patch 12 Hot Fix 3b |
affected | ||
< Yokohama Patch 13 Hot Fix 4 |
affected | ||
< Zurich Patch 7b Hot Fix 3 |
affected | ||
< Zurich Patch 8 Hot Fix 5 |
affected | ||
< Zurich Patch 9 Hot Fix 6 |
affected | ||
< Zurich Patch 10 Hot Fix 2m (m-branch) |
affected | ||
< Zurich Patch 10 Hot Fix 3 (standard) |
affected | ||
| … +7 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | 0 ~ Xanadu Patch 11 Hot Fix 7a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6876 | 10.0 CRITICAL | Sandbox Escape in ServiceNow AI Platform |
| CVE-2026-18886 | 10.0 CRITICAL | Unauthenticated Privilege Escalation via System Configuration Image Upload Processor |
| CVE-2026-18885 | 10.0 CRITICAL | Unauthenticated Remote Code Execution in GraphQL Composite Data API |
No comments yet