ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
The vulnerability results from improper input data validation (CWE-1287) in the Now Platform. An attacker without any credentials can submit a specially crafted network request, which will be processed by the platform in a way that allows arbitrary code execution in its context. The lack of authentication requirement and user interaction makes the attack particularly easy to conduct remotely.
An attacker can remotely execute arbitrary code in the context of the ServiceNow platform, which may lead to complete takeover of the instance, data theft, and further compromise of the environment.
Patches and hot fixes indicated by the vendor in KB articles KB1644293 and KB1645154 must be applied immediately. Instances hosted by ServiceNow received the update automatically; self-hosted customers and partners should manually implement the provided fixes.
ServiceNow Now Platform — Vancouver and Washington DC releases; detailed lists of patches and hot fixes are available in the vendor's support articles (KB1644293, KB1645154)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XServicenow
APPServicenowutahvancouverwashington_dc
CISA KEV — detailsi
- Vendori
- ServiceNow
- Producti
- Utah, Vancouver, and Washington DC Now Platform
- Added to KEVi
- July 29, 2024
- Remediation deadline (US Federal)i
- August 19, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
Related vulnerabilities
Krytyczna podatność RCE w ServiceNow Now Platform (input validation)
Zdalne wykonanie kodu w ServiceNow Now Platform (RCE bez uwierzytelnienia)
ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vul...
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...