FAIL › dossier
ServiceNow
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 50%
ServiceNow, a cloud-based IT solutions provider, has experienced high-severity remote code execution vulnerabilities, indicating potential weaknesses in its security posture.
PROFILE
CategoryIT Services and SoftwareWhat they doServiceNow is a cloud-based platform that provides workflow automation, IT service management (ITSM), and employee engagement solutions.
SECURITY POSTURE
Subject to internal failure history and external scrutiny.
Notable failures
- CVE-2024-5217: High [RCE] vulnerability in GlideExpression script
- CVE-2024-4879: High [RCE] vulnerability via jelly template injection in UI macros
Patterns: Repeated unauthenticated remote code execution vulnerabilities
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-07-29 | CVE-2024-5217 | high | ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code. |
| 2024-07-29 | CVE-2024-4879 | high | ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros. |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Government Community Cloud | Authorized | High |
Open questions: How has ServiceNow addressed these vulnerabilities? · What is the company's approach to security awareness and training for its employees?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:46:43.280711+00:00