- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-01-2018 08:37 AM
Hi all.
I'm a bit puzzled.
I've been using masked type variable in my catalog item for capturing SSN value.
Per ServiceNow documentation "Since a masked variable uses platform encryption using TripleDES, the values for this variable are also encrypted"
However, my experience is different. When I impersonate an ITIL user and when I go to "sc_item_option_mtom" table list view I am able to see un-encrypted variable values.
Am I missing something?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-17-2018 06:01 AM
I have upgraded my instance to London and this issue seems to be ongoing.
I am able to see un-encrypted masked variable value in "value" field of "sc_item_option" table.
I hope this vulnerability will be addressed soon.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-04-2018 05:19 PM
If that's true, that's a security bug
Please mark this response as correct or helpful if it assisted you with your question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-17-2018 06:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎09-25-2019 01:19 PM
in the mask variable's type specification, you will need to enable encryption

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎09-04-2020 07:28 AM