started · updated
ServiceNow patches critical vulnerabilities and partners with Wiz
ServiceNow has patched three critical vulnerabilities, each assigned a CVSS score of 10. These flaws included one allowing unauthenticated data modification in hosted instances, one enabling arbitrary code execution via a GraphQL interface, and another allowing arbitrary SQL commands to modify databases.
In a separate development, Wiz has partnered with ServiceNow to integrate high-fidelity cloud security data into existing ServiceNow workflows. This collaboration aims to help IT and security teams manage the challenges of migrating to the cloud, such as maintaining accurate inventories of ephemeral workloads, triaging security issues within ITSM, and prioritizing vulnerabilities and misconfigurations based on organizational compliance frameworks.