CRITICAL🇵🇱 Wersja polska

CVE-2024-8923

CVSS 9.3v4.0pub. 2024-10-29upd. 2024-11-27

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.

🤖 AI Analysis
How it works

The vulnerability consists of improper input validation in the Now Platform. An attacker can submit a specially crafted network request without needing to possess an account or authentication credentials, and the platform improperly processes the supplied data, leading to arbitrary code execution in the context of the application. The vulnerability is remotely accessible over the network without any additional prerequisites.

Impact

An unauthenticated attacker can remotely execute arbitrary code in the context of the ServiceNow Now Platform, which may lead to system takeover, data disclosure, or data modification.

Mitigation & patch

ServiceNow has deployed an update on all hosted instances automatically. Self-hosted customers and partners should immediately apply patches and hot fixes indicated by the vendor in KB1706070 article available in the ServiceNow support portal.

Who is affected

ServiceNow Now Platform — hosted instances and self-hosted environments of partners and customers in versions indicated in vendor references (KB1706070). ServiceNow has deployed the update on hosted instances and made it available to partners and self-hosted customers.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Servicenow

    APP
    Servicenow
    vancouverwashington_dcxanadu
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-4879CRITICAL9.3⚠ KEVPL ✓same product

ServiceNow Now Platform — zdalny RCE bez uwierzytelnienia (input validation)

CVE-2024-5217CRITICAL9.2⚠ KEVPL ✓same product

Krytyczna podatność RCE w ServiceNow Now Platform (input validation)

CVE-2022-43684CRITICAL9.9PL ✓same product

ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych

CVE-2024-8924HIGH8.7same product

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vul...

CVE-2018-7748HIGH8.8same product

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...