ServiceNow KB1553688
Public Simple List Widget Data Exposure (misconfiguration)
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
No EPSS score is published for this advisory yet; priority uses the available signals. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
A ServiceNow security advisory with no CVE (classed as a misconfiguration, not a platform
vulnerability). Public-facing Service Portal widgets (notably the Simple List / SimpleListWidget)
served by ACLs with no role, an empty condition, and an empty script allow an unauthenticated
actor to read records — including PII — by querying the widget directly. Publicly analysed by AppOmni
(Aaron Costello) in October 2023; ServiceNow responded by tightening OOB ACL defaults and restricting
ACLs that reference non-existent roles. The remediation is configuration, not a patch — see the
cross-linked ACL guidance (ACL-001) for the permit-all ACL pattern this exploits.
A closely related 2024 follow-up — public widgets able to read Knowledge Base articles secured by
User Criteria rather than ACLs (so UserIsAuthenticated did not apply) — is the same class of
exposure. Its distinct ServiceNow KB number is not publicly recoverable (login-gated); track it here
as related until the id is confirmed.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| All releases (configuration-dependent) | Mitigation, not a patch: restrict public ACLs (no role + empty condition + empty script). ServiceNow tightened OOB ACL defaults and restricted ACLs pointing at non-existent roles (Oct 2023). |
Source & attribution
ServiceNow KB1553688 (login-gated); public technical analysis by AppOmni (Aaron Costello). This is a misconfiguration advisory with no CVE — affected scope is configuration-dependent, not version-bound.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(i)
- DORA Art.9§1
- DORA Art.9§4(c)
- DORA RTS Art.21
- ISO A.8.3
- ISO A.5.15
- GDPR Art.32§1(b)
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.