ServiceNow CVE-2024-8924
Unauthenticated Blind SQL Injection in Now Platform Core
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
An unauthenticated blind SQL-injection flaw in Now Platform core that allows an attacker to infer and
exfiltrate database contents (confidentiality impact only). Addressed in ServiceNow's October 2024
Patching Program. NOT on the CISA KEV catalog as of authoring. Injection mechanics, detection, and
remediation for the encoded-query / SQL injection class are covered in the cross-linked KB article
CODE-006 — this signature carries only the version matrix and the exposure-window detection overlay.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Utah | Patch 10b Hot Fix 3 |
| Vancouver | Patch 8 Hot Fix 5 / Patch 9 Hot Fix 3b / Patch 10 Hot Fix 2 |
| Washington DC | Patch 4 Hot Fix 2b / Patch 5 Hot Fix 6 / Patch 6 Hot Fix 1 / Patch 7 |
| Xanadu | Patch 1 |
Source & attribution
Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-8924, retrieved 2026-06-08. The CNA record adds Utah (Patch 10b Hot Fix 3) beyond the families named in third-party mirrors. Same data in login-gated KB1706072. Corroborated by NVD + Tenable.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(e)
- DORA Art.9§1
- DORA Art.9§4(c)
- DORA RTS Art.16
- DORA RTS Art.21
- ISO A.8.3
- ISO A.8.28
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.