This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Servicenow First view 2024-10-29
Product Servicenow Last view 2024-10-29
Version vancouver Type Application
Update patch_9_hotfix_2a  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:servicenow:servicenow

Activity : Overall

Related : CVE

  Date Alert Description
7.5 2024-10-29 CVE-2024-8924

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...