UPDATEMore than 1,000 instances of ServiceNow knowledge bases (KBs) representing 45% of instances tested by AppOmni were found to have a misconfiguration that unintentionally exposed data from the KBs.Companies use ServiceNow KBs to store and share information in the form of articles that can help users find answers to questions, troubleshoot issues, and resolve IT service tasks.A Sept. 17 blog post by AppOmni researchers explained that this data can often be sensitive in nature. Personally identifiable information (PII), internal system details, and active credentials/tokens to live production systems were found in the case AppOmni reported.“In many of these cases, it was observed that organizations that have more than one instance of ServiceNow had consistently misconfigured KB access controls across each one,” wrote the AppOmni researchers. “This could indicate a systematic misunderstanding of KB access controls or possibly the accidental replication of at least one instance’s poor controls to another through cloning.”Dan Meged, senior research leader at Adaptive Shield, added that this misconfiguration exposed seemingly secured KB articles through a ServiceNow tool called widgets. In another Sept. 17 blog on the ServiceNow KB topic, Adaptive Shield researchers said widgets let hackers bypass the security controls put in place at the KB and page level, and directly access the content.Meged said attackers could easily do this at scale, exposing every article within KB. As part of the shared responsibility model, it’s up to organizations to prevent these leaks, said Meged. This past May, Meged said the Adaptive Shield research team he heads up discovered the misconfiguration in about 30% of the thousands of ServiceNow accounts the team reviewed and responsibly disclosed this exposure.“To remediate this issue, ServiceNow admins must set their ‘Can Read’ user criteria to non-public and add ‘guest user’ and ‘any user’ to ‘Cannot Read’ to prevent access to this content through a widget,” said Meged. “In addition, they must set all public pages to private. This is a serious misconfiguration that underscores the need for robust access controls and continuous monitoring."When asked for a response to the AppOmni and Adaptive Shield blogs, a spokesperson for ServiceNow said the company is aware of recent publications describing the potential for unintended access if KB articles are not configured to meet business needs. The company said several months ago, they contacted customers with detailed guidance on how to address this issue. In addition, to help protect customers whose KBs may still permit greater access than desired, ServiceNow said on Sept. 4 that it began to take proactive action designed to address customers’ KB configurations as appropriate. “We proactively work with customers on the ongoing safety of their security configurations to ensure they are properly structured and aligned to their intended purpose,” said ServiceNow. “We make these protocols extensible so our customers can configure them based on their unique security needs.”
Network Security, Patch/Configuration Management, Identity
ServiceNow ‘knowledge base’ misconfiguration leaks sensitive data
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
