ServiceNow CVE-2024-5217
Incomplete Disallowed-Input List in GlideExpression (SSTI RCE)
Risk & exploitation
EPSS (FIRST) estimates a very high likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
The second link in the July 2024 ServiceNow SSTI chain: an incomplete list of disallowed inputs in
GlideExpression script evaluation that bypasses the initial CVE-2024-4879 mitigation and re-enables
unauthenticated remote code execution. Added to the CISA KEV catalog on 2024-07-29 (remediation due
2024-08-19). Full technical detail and the combined chain narrative are in the cross-linked KB
article CVE-001 — this signature carries only the version matrix and the exposure-window detection
overlay.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Washington DC | Patch 1 Hot Fix 3b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 2 / Patch 4 / Patch 5 |
| Vancouver | Patch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 Hot Fix 1 / Patch 10 |
| Utah | Patch 10 Hot Fix 3 / Patch 10a Hot Fix 2 / Patch 10b Hot Fix 1 |
Source & attribution
Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-5217, retrieved 2026-06-08. NOTE: distinct from CVE-2024-4879 — 5217's Washington DC fix runs to Patch 5 and Utah includes Patch 10b; do not reuse 4879's matrix. Same data in login-gated KB1644293/KB1648313. Corroborated by NVD CPE + CISA KEV.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.9§2
- DORA Art.17§1
- DORA RTS Art.10
- DORA RTS Art.11
- DORA RTS Art.22
- ISO A.8.8
- ISO A.8.9
- ISO A.8.28
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.