CVE Tools

Introducing snowpick: Testing ServiceNow for Public Data Exposure

Bishop FoxBy Emilio Gallegos11 min read

ResearchServiceNow
Read at Bishop Fox

Below is the opening; the full story is at Bishop Fox.

From Bishop Fox

TL;DR

ServiceNow portals can expose backend records through public widgets and API endpoints that query backend tables, even when the visible portal appears locked down.
snowpick is a Bishop Fox-built tool that checks those paths from an unauthenticated session and separates real row access from count-only leaks. It produces small, reproducible evidence packages so testers can prove impact and defenders can fix the exact misconfiguration without bulk data collection. Get the tool on GitHub.…

Continue at Bishop Fox

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store