← All CVEs & advisories

ServiceNow CVE-2022-43684

ServiceNow Information Disclosure

InfoDisclosureCVSS 3.1 9.9Priority 20Disclosed 2023-06-13Verified

Risk & exploitation

PriorityMedium · 20/100
EPSS0.002 · 44.2th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.

Additional Details

This issue is present in the following supported ServiceNow releases:

* Quebec prior to Patch 10 Hot Fix 8b

* Rome prior to Patch 10 Hot Fix 1

* San Diego prior to Patch 7

* Tokyo prior to Tokyo Patch 1; and

* Utah prior to Utah General Availability

If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
UtahGeneral Availability (GA)
TokyoPatch 1
Source & attribution

Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2022-43684 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.

Check your instance for CVE-2022-43684

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.