Lucene search

K
cve[email protected]CVE-2022-38463
HistoryAug 23, 2022 - 7:15 p.m.

CVE-2022-38463

2022-08-2319:15:09
CWE-79
web.nvd.nist.gov
40
11
servicenow
san diego
patch
4b
6
reflected xss
logout
nvd

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

54.8%

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

Affected configurations

NVD
Node
servicenowservicenowMatchsan_diegopatch_4
OR
servicenowservicenowMatchsan_diegopatch_4a
OR
servicenowservicenowMatchsan_diegopatch_6

Social References

More

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

54.8%

Related for CVE-2022-38463