← Back

CVE-2021-45901

nvd nist
Published: Feb 10, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

Affected (7)

1 product
Servicenow
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Servicenow
Version jakarta p1
Version jakarta p2
Version jakarta p3
Version jakarta p3a
Version jakarta p3b
Version jakarta p4
Version jakarta p5

Timeline

No history available yet.