ServiceNow patches three maximum severity flaws that could put enterprise data at risk
Brief
Code injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems.
ServiceNow’s latest trio of maximum severity flaws shows that even AI-era platforms remain vulnerable to these techniques: The software provider has released patches for three bugs in its ServiceNow AI Platform that could be exploited via low-complexity code injection, SQL injection, and privilege escalation attacks, with no user interaction required.
Although its cloud-based instances have already been updated, ServiceNow advises self-hosted customers to upgrade or patch immediately.
“You never want to see a 10/10 critical,” said David Shipley of Beauceron Security. “And you really don’t want to see three drop in row unless it’s an Olympic judging panel.”
