ServiceNow CVE-2024-5217
Incomplete Disallowed-Input List in GlideExpression (SSTI RCE)
Risk & exploitation
EPSS (FIRST) estimates a very high likelihood of exploitation in the next 30 days (2026-09-02). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
The second link in the July 2024 ServiceNow SSTI chain: an incomplete list of disallowed inputs in GlideExpression script evaluation that bypasses the initial CVE-2024-4879 mitigation and re-enables unauthenticated remote code execution. Added to the CISA KEV catalog on 2024-07-29 (remediation due 2024-08-19). Full technical detail and the combined chain narrative are in the cross-linked KB article CVE-001 — this signature carries only the version matrix and the exposure-window detection overlay.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Washington DC | Patch 1 Hot Fix 3b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 2 / Patch 4 / Patch 5 |
| Vancouver | Patch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 Hot Fix 1 / Patch 10 |
| Utah | Patch 10 Hot Fix 3 / Patch 10a Hot Fix 2 / Patch 10b Hot Fix 1 |
Source & attribution
Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-5217, retrieved 2026-06-08. NOTE: distinct from CVE-2024-4879 — 5217's Washington DC fix runs to Patch 5 and Utah includes Patch 10b; do not reuse 4879's matrix. Same data in login-gated KB1644293/KB1648313. Corroborated by NVD CPE + CISA KEV.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.9§2
- DORA Art.17§1
- DORA RTS Art.10
- DORA RTS Art.11
- DORA RTS Art.22
- ISO A.8.8
- ISO A.8.9
- ISO A.8.28
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-5xx6-pf4v-cpf2
- https://nvd.nist.gov/vuln/detail/CVE-2024-5217
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1644293
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648313
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-5217
- https://www.cve.org/CVERecord?id=CVE-2024-5217
- https://www.darkreading.com/cloud-security/patchnow-servicenow-critical-rce-bugs-active-exploit
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.