Cloud know-how large ServiceNow seems to have notified a few of its enterprise clients {that a} software program bug on its platform was permitting anybody on the web to entry their information.
A information base article, which ServiceNow has hidden behind a login wall however has been shared on Reddit, says the corporate on June 5 patched some buyer cases to repair a bug that had allowed unauthenticated customers to “achieve better entry” to ServiceNow-hosted information than meant.
The bug allowed probably anybody to acquire information saved in buyer cases with out requiring credentials, resembling a password.
It’s not clear who had improper entry to ServiceNow clients, what information was accessed or taken, or if any group was concerned. Provided that the safety incident seems to stem from a data-exposing bug, it’s unclear if clients may have protected themselves from improper entry.
ServiceNow is a cloud computing large that permits 1000’s of its enterprise clients to automate their inner enterprise processes. Firms use the tech large’s platform to construct workflows that join to numerous apps and databases, resembling IT and HR programs, which can be utilized to routinely deal with repeat duties, like onboarding employees, resolving tech help tickets, and for chatbots.
As such, firms like ServiceNow are high-value targets for hackers because of the quantity of delicate information that they retailer, resembling buyer help tickets, which may embody passwords, keys and credentials.
ServiceNow stated the problem pertains to Australian buyer cases, however a number of folks on Reddit who will not be positioned in Australia say they’ve recognized proof of exterior entry to their ServiceNow cases. Community defenders shared an IP deal with, 51.159.98.241, stated to be an indicator of potential compromise if present in a buyer’s logs.
A spokesperson for ServiceNow didn’t instantly return TechCrunch’s electronic mail requesting remark and looking for solutions on what number of clients are affected, or how lengthy the bug had uncovered the information.
Whenever you buy by hyperlinks in our articles, we might earn a small fee. This doesn’t have an effect on our editorial independence.




