CVE-2024-5217

ServiceNow Utah, Vancouver, and Washington DC Now Platform: Incomplete List of Disallowed Inputs

As of , CVE-2024-5217 in ServiceNow Utah, Vancouver, and Washington DC Now Platform is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 29 July 2024
US federal deadline
19 August 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 29 July 2024EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: support.servicenow.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

CISA's description

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

The CVE record's description, from SN

CVE published
10 July 2024
Assigned by
SN
CVSS
9.2 Critical (CVSS 4.0, from the CNA)
CWE-184
Incomplete List of Disallowed Inputs
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Renamed from Utah, Vancouver, and Washington DC Now to Utah, Vancouver, and Washington DC Now Platform.

Utah, Vancouver, and Washington DC Now Platform: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-4879Improper Input ValidationServiceNow Utah, Vancouver, and Washington DC Now PlatformPatch this weekEPSS 0.990.99

Read further