← Back

CVE-2024-4879

Published: Jul 10, 2024Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: psirt@servicenow.com (Secondary)

Description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Affected (90)

1 product
Servicenow
Configuration A
46 vulnerable
Vulnerable SoftwareAffected Versions
Servicenow
Version utah
Version utah early_availability
Version utah patch_10
Version utah patch_10_hotfix_1
Version utah patch_10_hotfix_2
Version utah patch_10a
Version utah patch_10a_hotfix_1
Version utah patch_1
Version utah patch_1_hotfix_1
Version utah patch_1_hotfix_1a
Version utah patch_1_hotfix_1b
Version utah patch_1_hotfix_2
Version utah patch_2
Version utah patch_2_hotfix_1
Version utah patch_2_hotfix_2
Version utah patch_2_hotfix_3
Version utah patch_2_hotfix_4
Version utah patch_3
Version utah patch_3_hotfix_1
Version utah patch_3_hotfix_1b
Version utah patch_4
Version utah patch_4_hotfix_1
Version utah patch_4_hotfix_2
Version utah patch_4_hotfix_2a
Version utah patch_4_hotfix_2b
Version utah patch_4_hotfix_3
Version utah patch_4_hotfix_3b
Version utah patch_4_hotfix_4
Version utah patch_4_hotfix_4b
Version utah patch_4_hotfix_5
Version utah patch_5
Version utah patch_5_hotfix_1
Version utah patch_6
Version utah patch_6_hotfix_1
Version utah patch_6_hotfix_2
Version utah patch_7
Version utah patch_7_hotfix_1
Version utah patch_7_hotfix_2
Version utah patch_7a
Version utah patch_7b
Version utah patch_8
Version utah patch_8_hotfix_2
Version utah patch_9
Version utah patch_9_hotfix_1
Version utah patch_9_hotfix_1a
Version utah patch_9_hotfix_1b
Configuration B
36 vulnerable
Vulnerable SoftwareAffected Versions
Servicenow
Version vancouver
Version vancouver patch_10
Version vancouver patch_1
Version vancouver patch_1_hotfix_1
Version vancouver patch_2
Version vancouver patch_2_hotfix1a
Version vancouver patch_2_hotfix_1
Version vancouver patch_2_hotfix_1a
Version vancouver patch_2_hotfix_2
Version vancouver patch_2_hotfix_3
Version vancouver patch_3
Version vancouver patch_3_hotfix_1
Version vancouver patch_3_hotfix_2
Version vancouver patch_3_hotfix_3
Version vancouver patch_3_hotfix_4
Version vancouver patch_4
Version vancouver patch_4_hotfix_1
Version vancouver patch_4_hotfix_1a
Version vancouver patch_4_hotfix_1b
Version vancouver patch_4_hotfix_2b
Version vancouver patch_5
Version vancouver patch_5_hotfix_1
Version vancouver patch_6
Version vancouver patch_6_hotfix_1
Version vancouver patch_7
Version vancouver patch_7_hotfix_1
Version vancouver patch_7_hotfix_1a
Version vancouver patch_7_hotfix_2
Version vancouver patch_7_hotfix_2a
Version vancouver patch_7_hotfix_2b
Version vancouver patch_7_hotfix_3a
Version vancouver patch_8
Version vancouver patch_8_hotfix_1
Version vancouver patch_8_hotfix_2
Version vancouver patch_8_hotfix_3
Version vancouver patch_9
Configuration C
8 vulnerable
Vulnerable SoftwareAffected Versions
Servicenow
Version washington_dc
Version washington_dc patch_1
Version washington_dc patch_1_hotfix_1
Version washington_dc patch_1_hotfix_2
Version washington_dc patch_1_hotfix_2a
Version washington_dc patch_2
Version washington_dc patch_2_hotfix_1
Version washington_dc patch_3

References (7)

Source: psirt@servicenow.com
Press/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.