ServiceNow Reveals Security Issue Affecting Customer Data, But Won’t Reveal Much About What Really Happened



  • ServiceNow fixes an API flaw that allowed unauthenticated attackers to query some client instance tables
  • The issue primarily affects customers on the Australia version or older versions with custom settings
  • Administrators are encouraged to review the logs for /api/now/ related_list_edit requests, especially 51.159.98.241

ServiceNow has told some of its customers that cybercriminals were able to abuse a flaw in an API endpoint in an attempt to access their data.

In a support bulletin posted on its customer support portal, the company said it had fixed an issue “that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.”

Leave a Comment

Your email address will not be published. Required fields are marked *