EXPOSURES › CVE-2024-5217
CVE-2024-5217
HIGH ⌖ ON CISA KEV · EXPLOITEDServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.
An unauthenticated user could exploit the incomplete list of disallowed inputs in ServiceNow's GlideExpression script to execute remote code, enabling attackers to compromise the platform and potentially access sensitive data. This vulnerability poses a severe risk to DIB organizations relying on ServiceNow for case management and workflow automation, as it allows remote code execution without authentication. Organizations must immediately patch their ServiceNow instances and review their security configurations to prevent exploitation.
Shame score — The vulnerability allowed unauthenticated remote code execution, which is a critical security failure that could have been prevented with proper input validation and authentication checks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.
| PRODUCT | STATUS |
|---|---|
| Government Community Cloud ServiceNow |
Authorized |