ServiceNow reveals security issue affecting customer data, but doesn’t reveal much about what really happened


  • ServiceNow fixes an API flaw that allowed unauthenticated attackers to query certain client instance tables
  • The issue mainly affected customers of the Australian version or earlier versions with custom configurations.
  • Administrators are advised to review the logs for /api/now/Related_list_edit requests, particularly those originating from 51.159.98.241.

ServiceNow told some of its customers that cybercriminals were able to exploit a flaw in an API endpoint to try to access their data.

In a support bulletin posted to its customer support portal, the company said it had fixed an issue “that could allow an unauthenticated user, in certain circumstances, to gain broader than intended access to ServiceNow instances.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top