← All CVEs & advisories

ServiceNow CVE-2024-5217

Incomplete Disallowed-Input List in GlideExpression (SSTI RCE)

RCECVSS 4.0 9.2Priority 96CISA KEVDisclosed 2024-07-10Verified

Risk & exploitation

PriorityCritical · 96/100
EPSS0.941 · 99.9th pct
CISA KEVYes — known exploited
Public exploitYes — cisa-kev, nuclei

EPSS (FIRST) estimates a very high likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

The second link in the July 2024 ServiceNow SSTI chain: an incomplete list of disallowed inputs in

GlideExpression script evaluation that bypasses the initial CVE-2024-4879 mitigation and re-enables

unauthenticated remote code execution. Added to the CISA KEV catalog on 2024-07-29 (remediation due

2024-08-19). Full technical detail and the combined chain narrative are in the cross-linked KB

article CVE-001 — this signature carries only the version matrix and the exposure-window detection

overlay.

Affected releases & fixed-in

ReleaseFixed in
Washington DCPatch 1 Hot Fix 3b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 2 / Patch 4 / Patch 5
VancouverPatch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 Hot Fix 1 / Patch 10
UtahPatch 10 Hot Fix 3 / Patch 10a Hot Fix 2 / Patch 10b Hot Fix 1
Source & attribution

Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-5217, retrieved 2026-06-08. NOTE: distinct from CVE-2024-4879 — 5217's Washington DC fix runs to Patch 5 and Utah includes Patch 10b; do not reuse 4879's matrix. Same data in login-gated KB1644293/KB1648313. Corroborated by NVD CPE + CISA KEV.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2024-5217

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.