Executive brief
ServiceNow Now Platform releases (Utah, Vancouver, and Washington DC) contain an improper input validation vulnerability in UI macros. This flaw allows an unauthenticated remote attacker to perform Jelly template injection, leading to remote code execution.
Affected products
- ServiceNow Now Platform Utah All versions prior to patches/hotfixes released in July 2024
- ServiceNow Now Platform Vancouver All versions prior to patches/hotfixes released in July 2024
- ServiceNow Now Platform Washington DC All versions prior to patches/hotfixes released in July 2024
Timeline
- 2024-07-29: disclosed
- 2024-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-29: exploited: Reported as actively exploited in the wild.