Enterprise ServiceNow KBs exposed, leaking corporate data

A medical professional working on a digital device with icons floating in the air.
Image Credit: Shutterstock (Image credit: Shutterstock)

Research from AppOmni has claimed over 1,000 individual instances at ServiceNow which unintentionally exposed data from Knowledge Bases (KBs). This accounts for 45% of enterprises tested by the researchers.

ServiceNow offers KBs, which are self-service platforms “for users to store, share, and manage content”.

Aaron Costello, chief of SaaS security research at AppOmni, noted the risk comes from KBs that have been misconfigured by companies, leading to the exposed data. The applications affected were made public, so any threat actors could potentially see the information the bases contain.

Sensitive data

ServiceNow is used by 85% of the Fortune 500 to manage IT services and processes, and companies use the service to set up systems that define, automate, manage, and structure IT services.

The information found by researchers contained personally identifiable information (PII) such as names, credentials, phone numbers, and internal system details. Internal information such as HR processes or cyber attack response protocol was compromised, which could cause serious issues for a company’s cyber security.

“This is critical for organizations that use ServiceNow to know about because it can lead to the exposure of sensitive information such as PII, internal system information, and active credentials,” said Costello. “This highlights the urgent need for enterprises to routinely check and update their security configurations to prevent unauthorized access and protect their data assets.”

This is not the first time ServiceNow has presented vulnerabilities, with security flaws also spotted by researchers earlier this year.

ServiceNow introduced a round of updates in 2023 to their Access Controls Lists (ACLs) which were aimed at improving data protection but crucially these didn’t include KBs. Whilst externally facing information has legitimate uses, the KBs expose customer information which could be leveraged by threat actors.

To mitigate the risks of exposed information, the security researchers advise running routine diagnostics and communicating with software platform providers for the latest security updates.

More from TechRadar Pro

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

Read more
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
Data Breach
Thousands of widely-used public workspaces are leaking data
Data leak
Popular online bill paying site leaks data of thousands of users
API
Businesses are being plagued by API security risks - with nearly 99% affected
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening