8.8

CVE-2018-7748

Exploit
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ServicenowServicenow Versionjakarta
ServicenowServicenow Versionjakarta Updatep1
ServicenowServicenow Versionjakarta Updatep2
ServicenowServicenow Versionjakarta Updatep3
ServicenowServicenow Versionjakarta Updatep3a
ServicenowServicenow Versionjakarta Updatep3b
ServicenowServicenow Versionjakarta Updatep4
ServicenowServicenow Versionjakarta Updatep5
ServicenowServicenow Versionjakarta Updatep6
ServicenowServicenow Versionjakarta Updatep6a
ServicenowServicenow Versionjakarta Updatep7
ServicenowServicenow Versionjakarta Updatep8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.84% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.