CVE-2022-38463 describes a reflected Cross-Site Scripting (XSS) vulnerability in ServiceNow, specifically affecting versions through San Diego Patch 4b and Patch 6, within its logout functionality. This medium-severity vulnerability (CVSS 6.1) can be exploited with low attack complexity and no authentication, requiring user interaction, potentially leading to limited impact on confidentiality and integrity. While not actively exploited in the wild (not in KEV), a Nuclei template exists for detection, but there is no public Metasploit or ExploitDB exploit code, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
san_diegoCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:san_diego:patch_4:*:*:*:*:*:* | ||
san_diegoCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:san_diego:patch_4a:*:*:*:*:*:* | ||
san_diegoCPE matchmatch criteria | cpe:2.3:a:servicenow:servicenow:san_diego:patch_6:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.