CVE-2019-20768
Summary
| CVE | CVE-2019-20768 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-05 22:15:00 UTC |
| Updated | 2020-05-12 15:26:00 UTC |
| Description | ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Servicenow | It Service Management | kingston | - | All | All |
| Application | Servicenow | It Service Management | kingston | patch_1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_11 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_13 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_14 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_14-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3a-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-4 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_5 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-3 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-5 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_7 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_7-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_8 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_8-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_9 | All | All |
| Application | Servicenow | It Service Management | london | - | All | All |
| Application | Servicenow | It Service Management | london | patch_1 | All | All |
| Application | Servicenow | It Service Management | london | patch_1-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_1-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_2 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-5 | All | All |
| Application | Servicenow | It Service Management | london | patch_3 | All | All |
| Application | Servicenow | It Service Management | london | patch_3-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_3-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-5 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-6 | All | All |
| Application | Servicenow | It Service Management | london | patch_5 | All | All |
| Application | Servicenow | It Service Management | london | patch_5-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6 | All | All |
| Application | Servicenow | It Service Management | london | patch_6-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6a-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6b-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_7 | All | All |
| Application | Servicenow | It Service Management | madrid | - | All | All |
| Application | Servicenow | It Service Management | madrid | patch_0-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1-2 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_2 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3-2 | All | All |
| Application | Servicenow | It Service Management | kingston | - | All | All |
| Application | Servicenow | It Service Management | kingston | patch_1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_10-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_11 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_12-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_13 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_14 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_14-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_3a-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_4-4 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_5 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-2 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-3 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_6-5 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_7 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_7-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_8 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_8-1 | All | All |
| Application | Servicenow | It Service Management | kingston | patch_9 | All | All |
| Application | Servicenow | It Service Management | london | - | All | All |
| Application | Servicenow | It Service Management | london | patch_1 | All | All |
| Application | Servicenow | It Service Management | london | patch_1-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_1-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_2 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_2-5 | All | All |
| Application | Servicenow | It Service Management | london | patch_3 | All | All |
| Application | Servicenow | It Service Management | london | patch_3-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_3-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-2 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-3 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-4 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-5 | All | All |
| Application | Servicenow | It Service Management | london | patch_4-6 | All | All |
| Application | Servicenow | It Service Management | london | patch_5 | All | All |
| Application | Servicenow | It Service Management | london | patch_5-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6 | All | All |
| Application | Servicenow | It Service Management | london | patch_6-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6a-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_6b-1 | All | All |
| Application | Servicenow | It Service Management | london | patch_7 | All | All |
| Application | Servicenow | It Service Management | madrid | - | All | All |
| Application | Servicenow | It Service Management | madrid | patch_0-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_1-2 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_2 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3-1 | All | All |
| Application | Servicenow | It Service Management | madrid | patch_3-2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Responsible disclosure: Multiple stored XSS vulnerabilities discovered in ServiceNow ITSM by Outpost24 | Outpost 24 blog | MISC | outpost24.com | Exploit, Third Party Advisory |
| Cybersecurity Blog | Outpost24 | MISC | outpost24.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.