CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-4879

CVSS 9.3v4.0pub. 2024-07-10upd. 2025-11-03

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

🤖 AI Analysis
How it works

The vulnerability results from improper input data validation (CWE-1287) in the Now Platform. An attacker without any credentials can submit a specially crafted network request, which will be processed by the platform in a way that allows arbitrary code execution in its context. The lack of authentication requirement and user interaction makes the attack particularly easy to conduct remotely.

Impact

An attacker can remotely execute arbitrary code in the context of the ServiceNow platform, which may lead to complete takeover of the instance, data theft, and further compromise of the environment.

Mitigation & patch

Patches and hot fixes indicated by the vendor in KB articles KB1644293 and KB1645154 must be applied immediately. Instances hosted by ServiceNow received the update automatically; self-hosted customers and partners should manually implement the provided fixes.

Who is affected

ServiceNow Now Platform — Vancouver and Washington DC releases; detailed lists of patches and hot fixes are available in the vendor's support articles (KB1644293, KB1645154)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Servicenow

    APP
    Servicenow
    utahvancouverwashington_dc

CISA KEV — detailsi

Vendori
ServiceNow
Producti
Utah, Vancouver, and Washington DC Now Platform
Added to KEVi
July 29, 2024
Remediation deadline (US Federal)i
August 19, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 19 sierpnia 2024
CWE
References

Related vulnerabilities

CVE-2024-5217CRITICAL9.2⚠ KEVPL ✓same product

Krytyczna podatność RCE w ServiceNow Now Platform (input validation)

CVE-2024-8923CRITICAL9.3PL ✓same product

Zdalne wykonanie kodu w ServiceNow Now Platform (RCE bez uwierzytelnienia)

CVE-2022-43684CRITICAL9.9PL ✓same product

ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych

CVE-2024-8924HIGH8.7same product

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vul...

CVE-2018-7748HIGH8.8same product

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...