CVE-2018-7748
CVE-2018-7748 is a high-severity vulnerability in Servicenow with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- CVSS v2: 6.5
- EPSS exploit prediction: 3% (84th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Servicenow
- Published:
- Last modified:
Description
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.
Frequently asked questions
- What is CVE-2018-7748?
- report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.
- How severe is CVE-2018-7748?
- CVE-2018-7748 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-7748 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (84th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-7748?
- CVE-2018-7748 primarily affects Servicenow. In total, 12 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-7748?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-7748 published?
- CVE-2018-7748 was published on 2018-08-03 and last updated on 2026-06-17.
References
- https://telekomsecurity.github.io/2018/07/servicenow-privilege-escalation.html
- https://telekomsecurity.github.io/assets/advisories/20180104_ServiceNow_GlideInjection.txt
Affected products (12)
- cpe:2.3:a:servicenow:servicenow:jakarta:*:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p2:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3a:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3b:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p4:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p5:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p6:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p6a:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p7:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p8:*:*:*:*:*:*
More vulnerabilities in Servicenow
- CVE-2022-43684 — Critical (CVSS 9.9): ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow…
- CVE-2024-8923 — Critical (CVSS 9.8): ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability…
- CVE-2024-5217 — Critical (CVSS 9.8): ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and…
- CVE-2024-4879 — Critical (CVSS 9.8): ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now…
- CVE-2024-8924 — High (CVSS 7.5): ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This…
- CVE-2022-46389 — Medium (CVSS 6.1): There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix…
All CVEs affecting Servicenow →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…