ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
References
Link | Resource |
---|---|
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706070 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2024-10-29 16:15
Updated : 2024-11-27 19:31
NVD link : CVE-2024-8923
Mitre link : CVE-2024-8923
CVE.ORG link : CVE-2024-8923
JSON object : View
Products Affected
servicenow
- servicenow
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')