logo

CVE-2024-5217 - ServiceNow Incomplete List of Disallowed Inputs Vulnerability

Project:ServiceNow

Product:Utah, Vancouver, and Washington DC Now Platform

Date Added:2024-07-29Due Date:2024-08-19

Vulnerability Name

ServiceNow Incomplete List of Disallowed Inputs Vulnerability

Description

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648313

https://nvd.nist.gov/vuln/detail/CVE-2024-5217

Related News Articles

Critical ServiceNow RCE flaws actively exploited to steal credentialsJuly 26, 2024

Researchers Reveal ConfusedFunction Vulnerability in Google Cloud PlatformJuly 25, 2024