CVE-2024-5217 - ServiceNow Incomplete List of Disallowed Inputs Vulnerability
Project:ServiceNow
Product:Utah, Vancouver, and Washington DC Now Platform
Date Added:2024-07-29Due Date:2024-08-19
Vulnerability Name
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
Description
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648313
https://nvd.nist.gov/vuln/detail/CVE-2024-5217
Related News Articles
Critical ServiceNow RCE flaws actively exploited to steal credentialsJuly 26, 2024
Researchers Reveal ConfusedFunction Vulnerability in Google Cloud PlatformJuly 25, 2024