Skip to content
COOEY

FAIL › dossier

Utah, Vancouver, and Washington DC Now Platform

PRODUCT

· dossier confidence 20%

ServiceNow's Utah, Vancouver, and Washington DC Now Platform has faced multiple high-severity remote code execution vulnerabilities, highlighting potential security weaknesses in its AI platform.

PROFILE
CategoryProductWhat they doUtah, Vancouver, and Washington DC Now Platform is a product by ServiceNow, known for its AI platform used in enterprise IT service management and workflow automation. Websitehttps://service-now.com ↗
SECURITY POSTURE

The Utah, Vancouver, and Washington DC Now Platform has a history of unauthenticated remote code execution vulnerabilities, indicating a potential lack of robust security controls.

Notable failures
  • CVE-2024-5217: High [RCE] - Unauthenticated remote code execution vulnerability in GlideExpression script
  • CVE-2024-4879: High [RCE] - Unauthenticated remote code execution via jelly template injection in UI macros
Patterns: Repeated unauthenticated remote code execution vulnerabilities
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-07-29 CVE-2024-5217 high ServiceNow's GlideExpression script contained an unauthenticated remote code execution vulnerability that allowed attackers to execute arbitrary code.
2024-07-29 CVE-2024-4879 high ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.
Open questions: How has ServiceNow addressed these vulnerabilities? · What is the current security posture of the Utah, Vancouver, and Washington DC Now Platform?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:44:08.171633+00:00