Medium severity5.3NVD Advisory· Published Feb 10, 2022· Updated Jun 17, 2026
CVE-2021-45901
CVE-2021-45901
Description
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:servicenow:servicenow:jakarta:p1:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p2:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3a:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p3b:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p4:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:jakarta:p5:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/165989/ServiceNow-Orlando-Username-Enumeration.htmlnvdExploitThird Party Advisory
- www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/servicenow-username-enumeration-vulnerability-cve-2021-45901/nvdExploitThird Party Advisory
- www.trustwave.com/en-us/resources/security-resources/security-advisories/nvdVendor Advisory
News mentions
0No linked articles in our index yet.