Lucene search

K
cveMitreCVE-2018-7748
HistoryAug 03, 2018 - 6:29 p.m.

CVE-2018-7748

2018-08-0318:29:00
CWE-94
mitre
web.nvd.nist.gov
31
servicenow
jakarta
patch 8
cve-2018-7748
remote code execution
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.005

Percentile

77.6%

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via ‘${xyz}’ Glide Scripting Injection in the sysparm_media parameter.

Affected configurations

Nvd
Node
servicenowservicenowMatchjakarta
OR
servicenowservicenowMatchjakartap1
OR
servicenowservicenowMatchjakartap2
OR
servicenowservicenowMatchjakartap3
OR
servicenowservicenowMatchjakartap3a
OR
servicenowservicenowMatchjakartap3b
OR
servicenowservicenowMatchjakartap4
OR
servicenowservicenowMatchjakartap5
OR
servicenowservicenowMatchjakartap6
OR
servicenowservicenowMatchjakartap6a
OR
servicenowservicenowMatchjakartap7
OR
servicenowservicenowMatchjakartap8
VendorProductVersionCPE
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:*:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p2:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p3:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p3a:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p3b:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p4:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p5:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p6:*:*:*:*:*:*
servicenowservicenowjakartacpe:2.3:a:servicenow:servicenow:jakarta:p6a:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.005

Percentile

77.6%

Related for CVE-2018-7748