Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform

ServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.

The German Federal Office for Information Security (BSI) has issued an advisory regarding multiple vulnerabilities within the ServiceNow Now Platform and ServiceNow AI Platform. These flaws present significant security risks, potentially allowing remote, unauthenticated, or low-privileged attackers to execute arbitrary code, escalate system privileges, or manipulate the underlying database through SQL injection attacks. Given the enterprise-wide footprint of ServiceNow instances and their access to sensitive organizational data, successful exploitation could lead to total compromise of the application environment. Security teams should prioritize identifying their ServiceNow footprint and applying the latest vendor-supplied patches to mitigate these risks.

Impact

Successful exploitation of these vulnerabilities can result in full remote control of the application, unauthorized access to sensitive data via database manipulation, and lateral movement within the enterprise network through escalated administrative privileges. These platforms are core components in many large-scale IT and HR workflows; their compromise has the potential to impact entire organizational operations.

Recommendation

  • Perform an inventory of all ServiceNow Now Platform and AI Platform instances within the environment.
  • Monitor vendor security bulletins via the ServiceNow Support portal for specific patch availability and version guidance.
  • Review web application firewall (WAF) logs for anomalous request patterns targeting ServiceNow API endpoints, specifically searching for SQL injection syntax and code execution attempts.
  • Restrict access to ServiceNow administrative interfaces to trusted, authenticated management networks.

Immediate actions

Inventory all ServiceNow instances and check for pending security updates.

IT Operations 24h

Mitigations

Apply vendor-supplied patches as soon as they become available for the affected versions.

immediate IT Operations

All identified Now Platform and AI Platform instances