Live data from Hacker News

ServiceNow Insecure Access Control to Full Admin Takeover

x64.sh

41–50 of 81 posts

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#41
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

Feels like they have to boot a VM every time you click something.

Their cloud CMDB offerings are horrendous, and in my experience get bought before anyone gets a chance to let the blood out.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#42
post #14

Earlier quoted context omitted.

What makes it so bad? We are likely to get it next year . I feel it cannot be worse than the aberration we are currently using but I could be wrong :-/

You could be wrong... I worked at a place where we had like 20-30 different ERPs and they got SAP as a way to centralize the entire thing on one platform. However, during the migration they managed to recreate interfaces that resembled the old workflows people were used to, effectively having 20-30 customized SAP UIs with a common backend. It became such a clusterfuck the vendor (SAP) who we paid MASSIVE amounts of m…

I have this quote bookmarked, about ERPS:

"Most companies spend way too much time and money trying to make software work for their processes. Some of these processes haven't changed in years or even decades. Rather than customizing software to work for your processes, it's often easier to reevaluate processes around modern software."

You can have your ERP customized, but you cannot have your cake and eat it (without cost). Ramping up new trading partners, onboarding new staff, whatever it is.

One reason accounting people have it easier than us tech people is they've got a very good clear process. It's rare that anyone mucks with Accounts Payable / Accounts Receivable / Payroll.

So yeah, go on pretending your SMB that manufactures/ships/resells/distributes product/service _________ is unique and needs your own processes, it _will_ bite you in the butt.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#43

Earlier quoted context omitted.

What makes it so bad? We are likely to get it next year . I feel it cannot be worse than the aberration we are currently using but I could be wrong :-/

We used it locally at megacorp in place of the standard JIRA instance. As an end user I disliked it because it was painfully slow and the interface was awful. It broke browser navigation, if there were permalinks they were nearly impossible to find so most things couldn't easily be bookmarked, filtering was tedious and unintuitive. Some coworkers tried to write CLI tools and the API turned out to be as awkward as the…

[deleted]

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#45
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

I was at IBM for several years, can agree that ServiceNow is a steaming pile, like most of IBM. I spent the majority of my time fighting tooling over actually helping customers, lol.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#46
post #28

Earlier quoted context omitted.

I think you have a skewed perception of value add. ServiceNow conquered the software as a service industry like no other and will be around for decades to come. Developers and Admins may not like it because its development with bumpers for kids. End users dislike it because of the developers and admins. There may be some worth looking in the mirror to be had before you point the finger at a software platform for shor…

There must be some other platform that’s better than servicenow that does the same thing. I find it hard to believe this grotesque abomination is the state of the art in IT management.

There surely are. They don't, however, have the name recognition, the comparative availability of people who know how to deal with it, the ecosystem of vendors to sell you extensions, or, yeah, the sales function to push it at larger companies.

ServiceNow is big because everybody involved is incentivized to help make it big.

And FWIW, at my very very large company, it isn't even in the top 5 of shitty systems I have to deal with. ServiceNow at least works.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#47
post #28

Earlier quoted context omitted.

I think you have a skewed perception of value add. ServiceNow conquered the software as a service industry like no other and will be around for decades to come. Developers and Admins may not like it because its development with bumpers for kids. End users dislike it because of the developers and admins. There may be some worth looking in the mirror to be had before you point the finger at a software platform for shor…

There must be some other platform that’s better than servicenow that does the same thing. I find it hard to believe this grotesque abomination is the state of the art in IT management.

No, there isn’t. They all have pros and cons but none overall are “better”. ServiceNow is for large orgs with independent departments/orgs who need to use it differently. There’s BMC/Remedy but it’s just as convoluted and worse. Also Clarity used to be there.

There are many that are better at one one or two specific functions, sure. But none that have all the added features a large mature org would need.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#48
post #4

Of all the shitty enterprise software vendors, there is no platform I hate more than ServiceNow. What an abomination of something seemingly so simple made into something so horrendously complex and bloated. I was trying to explain to some new ServiceNow AE why we wouldn't be buying more product from them. Literally everyone who uses the product hates it - developers, admins, end users. It behaves like it is constantl…

Can you elaborate? A customer is in the process of implementing (Tokyo version?) it and it seems to have an intuitive, responsive UI. I'm judging it against Atlassian and Oracle EBS so I have low expectations.

Re: ServiceNow Insecure Access Control to Full Admin Takeover

#50

Almost exactly a year from report to disclosure. I'm sure it varies a lot, but is that a normal timeline for something this severe?

It can really depend on the nature of the vulnerability and who discovered it. Based on the timeline at the bottom of this article it seems like this was way too slow. Based on the cve information this was ranked as 9.8. The last time I dealt with a bug that bad it was log4j. It was found on a Tuesday, patched on a Thursday, announced on a Friday, and I redeployed all of our servers over the weekend. The most egregio…

I suspect the CVSS score has been over-estimated. For the "scope" metric, the "vulnerable component" and the "affected component" are both ServiceNow itself, so that should be "unchanged": https://security.stackexchange.com/a/129205

That drops you down to an 8.8. Also, log4shell was a 10.0, which got that extra .2 points from not requiring any privs, whereas this ServiceNow vuln requires "low" privs.

Post reply on HN