Lucene search

K
nvd[email protected]NVD:CVE-2022-38463
HistoryAug 23, 2022 - 7:15 p.m.

CVE-2022-38463

2022-08-2319:15:09
CWE-79
web.nvd.nist.gov
3
servicenow
san diego
patch
reflected xss
logout

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

54.7%

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

Affected configurations

Nvd
Node
servicenowservicenowMatchsan_diegopatch_4
OR
servicenowservicenowMatchsan_diegopatch_4a
OR
servicenowservicenowMatchsan_diegopatch_6
VendorProductVersionCPE
servicenowservicenowsan_diegocpe:2.3:a:servicenow:servicenow:san_diego:patch_4:*:*:*:*:*:*
servicenowservicenowsan_diegocpe:2.3:a:servicenow:servicenow:san_diego:patch_4a:*:*:*:*:*:*
servicenowservicenowsan_diegocpe:2.3:a:servicenow:servicenow:san_diego:patch_6:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

54.7%

Related for NVD:CVE-2022-38463