Loading
Generated remediation guidance and an executive summary. No account required.
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.
Use CWE-94, Servicenow vendor hub and Servicenow product page to widen CVE-2018-7748 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-4879, CVE-2024-5217 and CVE-2022-43684 for nearby disclosures in the same product family.