ServiceNow CVE-2021-45901
ServiceNow Information Disclosure
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
EPSS (FIRST) estimates a elevated likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Jakarta | TODO: verify — login-gated ServiceNow KB |
Source & attribution
GHSA GHSA-h956-vg6m-c6mm + NVD https://nvd.nist.gov/vuln/detail/CVE-2021-45901 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.
References
- http://packetstormsecurity.com/files/165989/ServiceNow-Orlando-Username-Enumeration.html
- https://github.com/advisories/GHSA-h956-vg6m-c6mm
- https://nvd.nist.gov/vuln/detail/CVE-2021-45901
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/servicenow-username-enumeration-vulnerability-cve-2021-45901/
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.