ServiceNow CVE-2022-46389
ServiceNow Cross-Site Scripting
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Quebec | TODO: verify — login-gated ServiceNow KB |
| Rome | TODO: verify — login-gated ServiceNow KB |
| San Diego | TODO: verify — login-gated ServiceNow KB |
| Tokyo | TODO: verify — login-gated ServiceNow KB |
| Utah | TODO: verify — login-gated ServiceNow KB |
Source & attribution
GHSA GHSA-9q54-3p63-8rwp + NVD https://nvd.nist.gov/vuln/detail/CVE-2022-46389 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.