ServiceNow KB1553688
Public Simple List Widget Data Exposure (misconfiguration)
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not been confirmed against the login-gated ServiceNow KB, so the exposure check returns NEEDS REVIEW. Review the references and your current patch level.
Risk & exploitation
No EPSS score is published for this advisory yet. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
A ServiceNow security advisory with no CVE (classed as a misconfiguration, not a platform vulnerability). Public-facing Service Portal widgets (notably the Simple List / SimpleListWidget) served by ACLs with no role, an empty condition, and an empty script allow an unauthenticated actor to read records — including PII — by querying the widget directly. Publicly analysed by AppOmni (Aaron Costello) in October 2023; ServiceNow responded by tightening OOB ACL defaults and restricting ACLs that reference non-existent roles. The remediation is configuration, not a patch — see the cross-linked ACL guidance (ACL-001) for the permit-all ACL pattern this exploits.
A closely related 2024 follow-up — public widgets able to read Knowledge Base articles secured by User Criteria rather than ACLs (so UserIsAuthenticated did not apply) — is the same class of exposure. Its distinct ServiceNow KB number is not publicly recoverable (login-gated); track it here as related until the id is confirmed.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| All releases (configuration-dependent) | Mitigation, not a patch: restrict public ACLs (no role + empty condition + empty script). ServiceNow tightened OOB ACL defaults and restricted ACLs pointing at non-existent roles (Oct 2023). |
Source & attribution
ServiceNow KB1553688 (login-gated); public technical analysis by AppOmni (Aaron Costello). This is a misconfiguration advisory with no CVE — affected scope is configuration-dependent, not version-bound.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(i)
- DORA Art.9§1
- DORA Art.9§4(c)
- DORA RTS Art.21
- ISO A.8.3
- ISO A.5.15
- GDPR Art.32§1(b)
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.