{"cve":{"cve_id":"CVE-2024-8924","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00509,"epss_percentile":0.39349,"epss_as_of":"2026-06-23","description":"ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.","published_at":"2024-10-29T16:14:38.836000Z","last_modified_at":null,"cvss_v3_score":7.5,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvss_v3_severity":"HIGH","cvss_v4_score":8.7,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cvss_v4_severity":"HIGH","ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-89"],"nvd_references":["https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:24:53.639719Z"},"effective_severity":"HIGH","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"N","value_label":"None"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"AT","name":"Attack Requirements","value":"N","value_label":"None"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"N","value_label":"None"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"N","value_label":"None"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"N","value_label":"None"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"N","value_label":"None"},{"metric":"SA","name":"Availability (Subsequent System)","value":"N","value_label":"None"}]},"affected":[{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Utah Patch 10b Hot Fix 3","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Utah Patch 10b Hot Fix 3"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Vancouver Patch 8 Hot Fix 5","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Vancouver Patch 8 Hot Fix 5"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Vancouver Patch 9 Hot Fix 3b","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Vancouver Patch 9 Hot Fix 3b"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Vancouver Patch 10 Hot Fix 2","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Vancouver Patch 10 Hot Fix 2"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Washington DC Patch 4 Hot Fix 2b","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Washington DC Patch 4 Hot Fix 2b"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Washington DC Patch 5 Hot Fix 6","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Washington DC Patch 5 Hot Fix 6"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Washington DC Patch 6 Hot Fix 1","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Washington DC Patch 6 Hot Fix 1"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Washington DC Patch 7","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Washington DC Patch 7"},{"vendor_slug":"servicenow","vendor_name":"ServiceNow","product_slug":"now-platform","product_name":"Now Platform","version_start":"0","version_start_inclusive":true,"version_end":"Xanadu Patch 1","version_end_inclusive":false,"cpe23_uri":"cve5:servicenow:now-platform:0:Xanadu Patch 1"}],"exploit_refs":[],"news":[],"references":[{"url":"https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2024-10-29T16:14:38.836000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:40:29.529971Z","label":"CVSS score revised","source":"cvelistv5"}]}