13.5 C
Canberra
Friday, September 20, 2024

Misconfigured ServiceNow Information Bases Expose Confidential Data


Customers of ServiceNow, a cloud-based platform used to handle IT companies and processes, might be unknowingly exposing confidential data, together with names, cellphone numbers, inner system particulars, and lively credentials.

Misconfiguration of Information Bases — self-service platforms inside ServiceNow the place customers can create, retailer, and share data similar to articles and guides — may result in unauthorised people getting access to the system. Many organisations use Information Bases as repositories of delicate inner data, similar to learn how to reset firm passwords, how to answer a cyberattack, knowledge associated to HR processes, and extra.

Based on a new weblog from SaaS safety platform supplier AppOmni, round 60% of exposures contain older variations of Information Bases which might be set as much as enable public entry by default. Others have “Person Standards” — guidelines that outline particular circumstances for customers to entry or contribute to Information Bases — which might be unintentionally granting entry to unauthenticated customers.

SEE: ServiceNow vs Jira Service Administration

ServiceNow is utilized by 85% of Fortune 500, and over a thousand situations are at present arrange incorrectly. Many organisations with a number of ServiceNow situations have been discovered to have constantly misconfigured Information Base entry controls, indicating that the settings have been both cloned throughout situations or a basic misunderstanding of how they work exists.

Aaron Costello, chief of SaaS safety analysis at AppOmni, mentioned, “This highlights the pressing want for enterprises to routinely test and replace their safety configurations to forestall unauthorised entry and defend their knowledge property.

“Understanding these points and learn how to mitigate them is crucial for sustaining strong safety in enterprise SaaS environments.”

This isn’t the primary time ServiceNow has been discovered to have been exposing delicate knowledge because of person misconfigurations. In 2020, one other researcher reported the same discovering the place Information Base articles have been publicly accessible by way of a now-secure UI web page.

Ben De Bont, chief data safety officer at ServiceNow, mentioned, “ServiceNow is dedicated to fostering collaboration with the safety neighborhood. We’re dedicated to defending our clients’ knowledge, and safety researchers are necessary companions in our ongoing efforts to enhance the safety of our merchandise.”

What are the Information Base misconfigurations?

AppOmni found three circumstances whereby companies have been placing their ServiceNow Information Bases prone to compromise:

  1. If utilizing an older model of ServiceNow the place the default settings for Information Base enable public entry when Person Standards aren’t arrange.
  2. If the “Any Person” and “Any person for kb” Person Standards are used as allowlists. Each of those grant entry to unauthenticated customers, which directors could not realise.
  3. If directors don’t configure denylists, permitting exterior customers to bypass entry controls.

SEE: 6 Greatest Governance, Danger & Compliance (GRC) Instruments for 2024

How attackers can acquire entry to the Information Bases

Based on Costello’s proof of idea, attackers can acquire entry to misconfigured Information Bases by way of Public Widgets, such because the “KB Article Web page” widget, which shows content material from a selected Information Base article.

An attacker can automate requests to search out and entry articles by way of the widget utilizing a software referred to as Burp Suite. That is simpler with the KB Article Web page widget, which makes use of a predictable format for article IDs of “KBXXXXXXX,” the place X represents a constructive integer.

Burp Suite’s Intruder characteristic can rapidly iterate over these integers and establish articles that could be uncovered unintentionally. It could actually then return the physique textual content, which can comprise the delicate knowledge of a number of unsecured articles without delay.

The best way to safe Information Bases towards unauthorised entry

Run common diagnostics on Information Base entry controls

ServiceNow’s Person Standards diagnostics software permits directors to find out which customers, each authenticated and unauthenticated, have the power to entry Information Bases and particular person articles.

Navigate to /get_public_knowledge_bases.do to establish public Information Bases, and the total diagnostics software at /km_diagnostics.do to establish the entry stage of public and personal customers to particular person articles.

Use Enterprise Guidelines to disclaim unauthenticated entry to Information Bases by default

Make sure the “sys_id 6c8ec5147711111016f35c207b5a9969” Enterprise Rule — which provides the Visitor Person to the “Can’t Learn and Can’t Contribute” Person Standards — is activated for Information Bases.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles