Open Internet by MindsNet
Auth Bypass Exploit in Service Now
A new auth bypass exploit has been discovered in a fully patched Service Now instance, allowing read access to system tables. The exploit has resulted in potential data loss, but Service Now's support has been unhelpful in providing information on what data was lost. The lack of logging for POST API calls is hindering investigation.
Computing & Technology, Computer Science, Programming Languages