Security Risk: Request catalog item for unauthenticated users
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2025 10:38 PM - edited 08-04-2025 10:32 PM
Hi All,
I am assessing the feasibility of publishing a request catalog item on external website that allows unauthenticated users to upload attachments as well.
My primary questions are:
What are ServiceNow's best practices regarding the exposure of request catalog items to unauthenticated users, and how can we align with them?
For those who have published catalog items for unauthenticated users, what specific security measures did you implement to safeguard the uploaded data and the system overall (e.g., against malware, unauthorised access, or data breaches)?
Thanks.
#employeecentre #recordproducer #customforms #externalusers