Impact
A SQL injection flaw in the ServiceNow AI Platform’s dynamic schema ORDER BY clause allows an unauthenticated user to run arbitrary SQL statements against the instance’s underlying database. This flaw can be exploited to read, alter, or delete data beyond the user’s intended permissions, effectively compromising confidential data and disrupting database integrity.
Affected Systems
The vulnerability affects ServiceNow AI Platform. Version information was not disclosed in the advisory, so all installations of the AI Platform that have not yet applied the update are potentially vulnerable.
Risk and Exploitability
The CVSS score of 10 marks this issue as critical, and while no exploitation has been reported to date and it is not listed in CISA’s KEV catalog, the EPSS score of 0.00238 indicates a very low but non‑zero likelihood of exploitation. An attacker with unauthenticated access to the exposed interface can directly inject malicious SQL, making the vulnerability highly likely to be abused if left unpatched.
OpenCVE Enrichment