CVE-2018-7748 describes a critical vulnerability in ServiceNow Release Jakarta Patch 8 and earlier, allowing remote attackers to execute arbitrary code. This is achieved through Glide Scripting Injection via the sysparm_media parameter in report_viewer.do. The vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability risks, exploitable over the network with low attack complexity. Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
jakartaCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:jakarta:*:*:*:*:*:*:* | ||
jakartaCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:* | ||
jakartaCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:jakarta:p2:*:*:*:*:*:* | ||
jakartaCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:jakarta:p3:*:*:*:*:*:* | ||
jakartaCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:jakarta:p3a:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.