7.5

CVE-2024-8924

Unauthenticated Blind SQL Injection in Core Platform

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Servicenow ≫ Servicenow Version xanadu Update -
Servicenow ≫ Servicenow Version xanadu Update early_availability
Servicenow ≫ Servicenow Version xanadu Update early_availability_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update -
Servicenow ≫ Servicenow Version vancouver Update early_availability
Servicenow ≫ Servicenow Version vancouver Update early_availability_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update early_availability_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_1
Servicenow ≫ Servicenow Version vancouver Update patch_1_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_10
Servicenow ≫ Servicenow Version vancouver Update patch_10_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_2
Servicenow ≫ Servicenow Version vancouver Update patch_2_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_2_hotfix_1a
Servicenow ≫ Servicenow Version vancouver Update patch_2_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_2_hotfix_3
Servicenow ≫ Servicenow Version vancouver Update patch_2_hotfix1a
Servicenow ≫ Servicenow Version vancouver Update patch_3
Servicenow ≫ Servicenow Version vancouver Update patch_3_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_3_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_3_hotfix_3
Servicenow ≫ Servicenow Version vancouver Update patch_3_hotfix_4
Servicenow ≫ Servicenow Version vancouver Update patch_4
Servicenow ≫ Servicenow Version vancouver Update patch_4_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_4_hotfix_1a
Servicenow ≫ Servicenow Version vancouver Update patch_4_hotfix_1b
Servicenow ≫ Servicenow Version vancouver Update patch_4_hotfix_2b
Servicenow ≫ Servicenow Version vancouver Update patch_5
Servicenow ≫ Servicenow Version vancouver Update patch_5_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_6
Servicenow ≫ Servicenow Version vancouver Update patch_6_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_6_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_7
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_1a
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_2a
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_2b
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_3a
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_3b
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotfix_4
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotifix_1a
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotifix_1b
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotifix_2a
Servicenow ≫ Servicenow Version vancouver Update patch_7_hotifix_2b
Servicenow ≫ Servicenow Version vancouver Update patch_8
Servicenow ≫ Servicenow Version vancouver Update patch_8_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_8_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_8_hotfix_3
Servicenow ≫ Servicenow Version vancouver Update patch_8_hotfix_4
Servicenow ≫ Servicenow Version vancouver Update patch_8_hotfix_5
Servicenow ≫ Servicenow Version vancouver Update patch_9
Servicenow ≫ Servicenow Version vancouver Update patch_9_hotfix_1
Servicenow ≫ Servicenow Version vancouver Update patch_9_hotfix_2
Servicenow ≫ Servicenow Version vancouver Update patch_9_hotfix_2a
Servicenow ≫ Servicenow Version vancouver Update patch_9_hotfix_2b
Servicenow ≫ Servicenow Version vancouver Update patch_9_hotfix_3a
Servicenow ≫ Servicenow Version washington_dc Update -
Servicenow ≫ Servicenow Version washington_dc Update early_availability
Servicenow ≫ Servicenow Version washington_dc Update early_availability_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_1
Servicenow ≫ Servicenow Version washington_dc Update patch_1_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_1_hotfix_2
Servicenow ≫ Servicenow Version washington_dc Update patch_1_hotfix_2a
Servicenow ≫ Servicenow Version washington_dc Update patch_1_hotfix_2b
Servicenow ≫ Servicenow Version washington_dc Update patch_1_hotfix_3b
Servicenow ≫ Servicenow Version washington_dc Update patch_2
Servicenow ≫ Servicenow Version washington_dc Update patch_2_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_2_hotfix_2
Servicenow ≫ Servicenow Version washington_dc Update patch_3
Servicenow ≫ Servicenow Version washington_dc Update patch_3_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_3_hotfix_2
Servicenow ≫ Servicenow Version washington_dc Update patch_3_hotfix_3
Servicenow ≫ Servicenow Version washington_dc Update patch_4
Servicenow ≫ Servicenow Version washington_dc Update patch_4_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_4_hotfix_1a
Servicenow ≫ Servicenow Version washington_dc Update patch_4_hotfix_1b
Servicenow ≫ Servicenow Version washington_dc Update patch_4_hotfix_2
Servicenow ≫ Servicenow Version washington_dc Update patch_4_hotfix_2a
Servicenow ≫ Servicenow Version washington_dc Update patch_5
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_1
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_2
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_3
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_4
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_5
Servicenow ≫ Servicenow Version washington_dc Update patch_5_hotfix_6
Servicenow ≫ Servicenow Version washington_dc Update patch_6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.4
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@servicenow.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
psirt@servicenow.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072
Vendor Advisory