← All CVEs & advisories

ServiceNow CVE-2022-46389

ServiceNow Cross-Site Scripting

XSSCVSS 3.1 6.1Priority 12Disclosed 2023-04-17Unverified

Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.

Risk & exploitation

PriorityLow · 12/100
EPSS0.007 · 72.0th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
QuebecTODO: verify — login-gated ServiceNow KB
RomeTODO: verify — login-gated ServiceNow KB
San DiegoTODO: verify — login-gated ServiceNow KB
TokyoTODO: verify — login-gated ServiceNow KB
UtahTODO: verify — login-gated ServiceNow KB
Source & attribution

GHSA GHSA-9q54-3p63-8rwp + NVD https://nvd.nist.gov/vuln/detail/CVE-2022-46389 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.

Check your instance for CVE-2022-46389

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.