A remote, anonymous attacker can exploit a vulnerability in the ServiceNow AI Platform to execute arbitrary code.
| Vendor | Product | Versions |
|---|---|---|
| servicenow | ai platform | 0, 0, 0, 0, 0, 0, 0, Brazil EA, Brazil GA, Australia Patch 2, Zurich Patch 7b, Zurich Patch 9, Yokohama Patch 12 Hot Fix 1b, Yokohama Patch 13 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| servicenow | ai platform | cert_advisory | 90% |
Added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) and new tags identifying this as a pre-auth RCE with code injection being actively exploited in the wild.
Updated CVSS score to 9.5 and clarified that patches were deployed to hosted instances.
Updated severity to CRITICAL, added new affected versions, and included CWE-94.
Updated description with new technical details and changed severity to HIGH, indicating that exploitation is possible.
Updated severity to CRITICAL, corrected exploit availability to false, and provided a new description with additional details.
Initial creation