HIGH🇵🇱 Wersja polska

CVE-2024-8924

CVSS 8.7v4.0pub. 2024-10-29upd. 2024-11-27

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Servicenow

    APP
    Servicenow
    vancouverwashington_dcxanadu
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-5217CRITICAL9.2⚠ KEVPL ✓same product

Krytyczna podatność RCE w ServiceNow Now Platform (input validation)

CVE-2024-4879CRITICAL9.3⚠ KEVPL ✓same product

ServiceNow Now Platform — zdalny RCE bez uwierzytelnienia (input validation)

CVE-2024-8923CRITICAL9.3PL ✓same product

Zdalne wykonanie kodu w ServiceNow Now Platform (RCE bez uwierzytelnienia)

CVE-2022-43684CRITICAL9.9PL ✓same product

ServiceNow: pominięcie kontroli dostępu ACL umożliwia dostęp do wrażliwych danych

CVE-2018-7748HIGH8.8same product

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrar...