ServiceNow Addresses Input Validation Vulnerability in Now Platform
CVE-2024-8923

10CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
29 October 2024

What is CVE-2024-8923?

An input validation vulnerability identified in ServiceNow's Now Platform could allow an unauthenticated user to execute remote code. This flaw poses significant risks as it could potentially enable attackers to manipulate system behavior and gain unauthorized access to sensitive data. ServiceNow has promptly addressed this issue by deploying updates to hosted instances, along with providing necessary patches and hot fixes to both partners and self-hosted customers, ensuring the integrity and security of the Now Platform.

Affected Version(s)

Now Platform 0

Now Platform 0

Now Platform 0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

T-Mobile
.