← All CVEs & advisories

ServiceNow CVE-2024-8924

Unauthenticated Blind SQL Injection in Now Platform Core

SQLiCVSS 4.0 8.7Priority 18Disclosed 2024-10-29Verified

Risk & exploitation

PriorityMedium · 18/100
EPSS0.006 · 70.5th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

An unauthenticated blind SQL-injection flaw in Now Platform core that allows an attacker to infer and

exfiltrate database contents (confidentiality impact only). Addressed in ServiceNow's October 2024

Patching Program. NOT on the CISA KEV catalog as of authoring. Injection mechanics, detection, and

remediation for the encoded-query / SQL injection class are covered in the cross-linked KB article

CODE-006 — this signature carries only the version matrix and the exposure-window detection overlay.

Affected releases & fixed-in

ReleaseFixed in
UtahPatch 10b Hot Fix 3
VancouverPatch 8 Hot Fix 5 / Patch 9 Hot Fix 3b / Patch 10 Hot Fix 2
Washington DCPatch 4 Hot Fix 2b / Patch 5 Hot Fix 6 / Patch 6 Hot Fix 1 / Patch 7
XanaduPatch 1
Source & attribution

Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-8924, retrieved 2026-06-08. The CNA record adds Utah (Patch 10b Hot Fix 3) beyond the families named in third-party mirrors. Same data in login-gated KB1706072. Corroborated by NVD + Tenable.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2024-8924

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.