AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-46389

MEDIUM · CVSS 6.1 EPSS 0.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-04-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-46389
Severity
MEDIUM
CVSS
6.1
EPSS
0.60%
Java

Original NVD Description

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.