Misconfigured ServiceNow Data Bases Expose Confidential Info


Customers of ServiceNow, a cloud-based platform used to handle IT companies and processes, may very well be unknowingly exposing confidential info, together with names, telephone numbers, inner system particulars, and energetic credentials.

Misconfiguration of Data Bases — self-service platforms inside ServiceNow the place customers can create, retailer, and share info akin to articles and guides — may result in unauthorised people getting access to the system. Many organisations use Data Bases as repositories of delicate inner info, akin to reset firm passwords, how to reply to a cyberattack, knowledge associated to HR processes, and extra.

In keeping with a new weblog from SaaS safety platform supplier AppOmni, round 60% of exposures contain older variations of Data Bases which are set as much as enable public entry by default. Others have “Consumer Standards” — guidelines that outline particular situations for customers to entry or contribute to Data Bases — which are unintentionally granting entry to unauthenticated customers.

SEE: ServiceNow vs Jira Service Administration

ServiceNow is utilized by 85% of Fortune 500, and over a thousand situations are presently arrange incorrectly. Many organisations with a number of ServiceNow situations had been discovered to have constantly misconfigured Data Base entry controls, indicating that the settings had been both cloned throughout situations or a elementary misunderstanding of how they work exists.

Aaron Costello, chief of SaaS safety analysis at AppOmni, stated, “This highlights the pressing want for enterprises to routinely verify and replace their safety configurations to forestall unauthorised entry and shield their knowledge property.

“Understanding these points and mitigate them is important for sustaining strong safety in enterprise SaaS environments.”

This isn’t the primary time ServiceNow has been discovered to have been exposing delicate knowledge resulting from person misconfigurations. In 2020, one other researcher reported an analogous discovering the place Data Base articles had been publicly accessible by means of a now-secure UI web page.

Ben De Bont, chief info safety officer at ServiceNow, stated, “ServiceNow is dedicated to fostering collaboration with the safety group. We’re dedicated to defending our clients’ knowledge, and safety researchers are essential companions in our ongoing efforts to enhance the safety of our merchandise.”

What are the Data Base misconfigurations?

AppOmni found three circumstances whereby companies had been placing their ServiceNow Data Bases susceptible to compromise:

  1. If utilizing an older model of ServiceNow the place the default settings for Data Base enable public entry when Consumer Standards aren’t arrange.
  2. If the “Any Consumer” and “Any person for kb” Consumer Standards are used as allowlists. Each of those grant entry to unauthenticated customers, which directors might not realise.
  3. If directors don’t configure denylists, permitting exterior customers to bypass entry controls.

SEE: 6 Greatest Governance, Danger & Compliance (GRC) Instruments for 2024

How attackers can acquire entry to the Data Bases

In keeping with Costello’s proof of idea, attackers can acquire entry to misconfigured Data Bases by means of Public Widgets, such because the “KB Article Web page” widget, which shows content material from a particular Data Base article.

An attacker can automate requests to search out and entry articles by means of the widget utilizing a software referred to as Burp Suite. That is simpler with the KB Article Web page widget, which makes use of a predictable format for article IDs of “KBXXXXXXX,” the place X represents a constructive integer.

Burp Suite’s Intruder characteristic can rapidly iterate over these integers and determine articles which may be uncovered unintentionally. It will probably then return the physique textual content, which can comprise the delicate knowledge of a number of unsecured articles without delay.

The best way to safe Data Bases towards unauthorised entry

Run common diagnostics on Data Base entry controls

ServiceNow’s Consumer Standards diagnostics software permits directors to find out which customers, each authenticated and unauthenticated, have the power to entry Data Bases and particular person articles.

Navigate to /get_public_knowledge_bases.do to determine public Data Bases, and the total diagnostics software at /km_diagnostics.do to determine the entry stage of public and personal customers to particular person articles.

Use Enterprise Guidelines to disclaim unauthenticated entry to Data Bases by default

Make sure the “sys_id 6c8ec5147711111016f35c207b5a9969” Enterprise Rule — which provides the Visitor Consumer to the “Can’t Learn and Can’t Contribute” Consumer Standards — is activated for Data Bases.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles