CVE-2024-5217

EUVD-2024-46457
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP
servicenowservicenow
𝑥
< utah_patch_10_hot_fix_3
ADP
servicenowservicenow
𝑥
< utah_patch_10a_hot_fix_2
ADP
servicenowservicenow
𝑥
< utah_patch_10b_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_6_hot_fix_2
ADP
servicenowservicenow
𝑥
< vancouver_patch_7_hot_fix_3b
ADP
servicenowservicenow
𝑥
< vancouver_patch_8_hot_fix_4
ADP
servicenowservicenow
𝑥
< vancouver_patch_9_hot_fix_1
ADP
servicenowservicenow
𝑥
< vancouver_patch_10
ADP
servicenowservicenow
𝑥
< washington_dc_patch_1_hot_fix_3b
ADP
servicenowservicenow
𝑥
< washington_dc_patch_2_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_3_hot_fix_2
ADP
servicenowservicenow
𝑥
< washington_dc_patch_4
ADP
servicenowservicenow
𝑥
< washington_dc_patch_5
ADP