ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configuration. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Servicenow
Servicenow servicenow |
|
| Vendors & Products |
Servicenow
Servicenow servicenow |
Fri, 10 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configuration. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so. | |
| Title | Reflected Cross Site Scripting in ServiceNow AI Platform | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SN
Published:
Updated: 2025-10-10T18:35:33.224Z
Reserved: 2025-10-07T16:35:31.924Z
Link: CVE-2025-11449
Updated: 2025-10-10T18:35:29.672Z
Status : Awaiting Analysis
Published: 2025-10-10T02:15:38.440
Modified: 2025-10-14T19:37:28.107
Link: CVE-2025-11449
No data.
OpenCVE Enrichment
Updated: 2025-10-10T11:17:26Z