CVE-2022-46886: ServiceNow

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.

Affected products

  • ServiceNow ServiceNow: version quebec only; version rome only; version san_diego only; version tokyo only

Published 2023-04-14. Last modified 2026-06-17.