← All CVEs & advisories

ServiceNow KB1553688

Public Simple List Widget Data Exposure (misconfiguration)

AccessControlPriority 0Disclosed 2023-10-14Unverified

Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not been confirmed against the login-gated ServiceNow KB, so the exposure check returns NEEDS REVIEW. Review the references and your current patch level.

Risk & exploitation

PriorityLow · 0/100
EPSSnot published
CISA KEVNo
Public exploitNone indexed

No EPSS score is published for this advisory yet. Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

A ServiceNow security advisory with no CVE (classed as a misconfiguration, not a platform vulnerability). Public-facing Service Portal widgets (notably the Simple List / SimpleListWidget) served by ACLs with no role, an empty condition, and an empty script allow an unauthenticated actor to read records — including PII — by querying the widget directly. Publicly analysed by AppOmni (Aaron Costello) in October 2023; ServiceNow responded by tightening OOB ACL defaults and restricting ACLs that reference non-existent roles. The remediation is configuration, not a patch — see the cross-linked ACL guidance (ACL-001) for the permit-all ACL pattern this exploits.

A closely related 2024 follow-up — public widgets able to read Knowledge Base articles secured by User Criteria rather than ACLs (so UserIsAuthenticated did not apply) — is the same class of exposure. Its distinct ServiceNow KB number is not publicly recoverable (login-gated); track it here as related until the id is confirmed.

Affected releases & fixed-in

ReleaseFixed in
All releases (configuration-dependent)Mitigation, not a patch: restrict public ACLs (no role + empty condition + empty script). ServiceNow tightened OOB ACL defaults and restricted ACLs pointing at non-existent roles (Oct 2023).
Source & attribution

ServiceNow KB1553688 (login-gated); public technical analysis by AppOmni (Aaron Costello). This is a misconfiguration advisory with no CVE — affected scope is configuration-dependent, not version-bound.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for KB1553688

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.

ServiceNow KB1553688: affected versions & exposure check — Nowisor | nowisor