Skip to content
COOEY

FAIL › dossier

ServiceNow

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 50%

ServiceNow, a cloud-based IT solutions provider, has experienced high-severity remote code execution vulnerabilities, indicating potential weaknesses in its security posture.

PROFILE
CategoryIT Services and SoftwareWhat they doServiceNow is a cloud-based platform that provides workflow automation, IT service management (ITSM), and employee engagement solutions.
SECURITY POSTURE

Subject to internal failure history and external scrutiny.

Notable failures
  • CVE-2024-5217: High [RCE] vulnerability in GlideExpression script
  • CVE-2024-4879: High [RCE] vulnerability via jelly template injection in UI macros
Patterns: Repeated unauthenticated remote code execution vulnerabilities
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-07-29 CVE-2024-5217 high ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.
2024-07-29 CVE-2024-4879 high ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
Government Community CloudAuthorizedHigh
Open questions: How has ServiceNow addressed these vulnerabilities? · What is the company's approach to security awareness and training for its employees?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:46:43.280711+00:00