Impact
ServiceNow has identified an unauthenticated SQL injection flaw in its AI Platform. An attacker who can send crafted requests to the platform could execute arbitrary SQL code against the underlying database, allowing the attacker to read sensitive data or modify application data beyond the intended permissions. The weakness stems from insufficient input validation, aligning with CWE-89, and would directly compromise the confidentiality and integrity of instance data.
Affected Systems
Affected products include the ServiceNow AI Platform. No specific version numbers are disclosed in the advisory; therefore, all deployments of the AI Platform should be evaluated for the presence of the flaw until vendor guidance is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, highlighting its severe impact. EPSS information is not available, and the flaw is not listed in CISA’s KEV catalog, but its high severity suggests that exploitation could be highly damaging if leveraged. The likely attack vector involves unauthenticated requests to the AI Platform’s web or API endpoints, and no malicious exploitation has been reported yet, though the potential for abuse remains. Organizations should treat this as a critical issue pending patch deployment.
OpenCVE Enrichment