Executive brief
ServiceNow Now Platform contains an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated remote attacker can exploit this to execute arbitrary code within the context of the platform.
Affected products
- ServiceNow Now Platform Washington DC Prior to June 2024 patches
- ServiceNow Now Platform Vancouver Prior to June 2024 patches
- ServiceNow Now Platform Utah Prior to June 2024 patches
Timeline
- 2024-06: patched: Patches and hotfixes released during the June 2024 patching cycle.
- 2024-07-29: disclosed
- 2024-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-07-29: exploited: Reported as actively exploited in the wild.