CVE-2024-8924: Unauthenticated Blind SQL Injection in Core Platform

Published Oct 29, 2024
·
Updated

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.

Affected Software

87 affected components
ServiceNow ServiceNow=xanadu
ServiceNow ServiceNow=xanadu-early_availability
ServiceNow ServiceNow=xanadu-early_availability_hotfix_1
ServiceNow ServiceNow=vancouver
ServiceNow ServiceNow=vancouver-early_availability
ServiceNow ServiceNow=vancouver-early_availability_hotfix_1
ServiceNow ServiceNow=vancouver-early_availability_hotfix_2
ServiceNow ServiceNow=vancouver-patch_1
ServiceNow ServiceNow=vancouver-patch_1_hotfix_1
ServiceNow ServiceNow=vancouver-patch_10
ServiceNow ServiceNow=vancouver-patch_10_hotfix_1
ServiceNow ServiceNow=vancouver-patch_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_2_hotfix_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_3
ServiceNow ServiceNow=vancouver-patch_2_hotfix1a
ServiceNow ServiceNow=vancouver-patch_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_1
ServiceNow ServiceNow=vancouver-patch_3_hotfix_2
ServiceNow ServiceNow=vancouver-patch_3_hotfix_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_4
ServiceNow ServiceNow=vancouver-patch_4
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1b
ServiceNow ServiceNow=vancouver-patch_4_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_5
ServiceNow ServiceNow=vancouver-patch_5_hotfix_1
ServiceNow ServiceNow=vancouver-patch_6
ServiceNow ServiceNow=vancouver-patch_6_hotfix_1
ServiceNow ServiceNow=vancouver-patch_6_hotfix_2
ServiceNow ServiceNow=vancouver-patch_7
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_7_hotfix_3a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_3b
ServiceNow ServiceNow=vancouver-patch_7_hotfix_4
ServiceNow ServiceNow=vancouver-patch_7_hotifix_1a
ServiceNow ServiceNow=vancouver-patch_7_hotifix_1b
ServiceNow ServiceNow=vancouver-patch_7_hotifix_2a
ServiceNow ServiceNow=vancouver-patch_7_hotifix_2b
ServiceNow ServiceNow=vancouver-patch_8
ServiceNow ServiceNow=vancouver-patch_8_hotfix_1
ServiceNow ServiceNow=vancouver-patch_8_hotfix_2
ServiceNow ServiceNow=vancouver-patch_8_hotfix_3
ServiceNow ServiceNow=vancouver-patch_8_hotfix_4
ServiceNow ServiceNow=vancouver-patch_8_hotfix_5
ServiceNow ServiceNow=vancouver-patch_9
ServiceNow ServiceNow=vancouver-patch_9_hotfix_1
ServiceNow ServiceNow=vancouver-patch_9_hotfix_2
ServiceNow ServiceNow=vancouver-patch_9_hotfix_2a
ServiceNow ServiceNow=vancouver-patch_9_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_9_hotfix_3a
ServiceNow ServiceNow=washington_dc
ServiceNow ServiceNow=washington_dc-early_availability
ServiceNow ServiceNow=washington_dc-early_availability_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2a
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2b
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_3b
ServiceNow ServiceNow=washington_dc-patch_2
ServiceNow ServiceNow=washington_dc-patch_2_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_2_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_3
ServiceNow ServiceNow=washington_dc-patch_3_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_3_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_3_hotfix_3
ServiceNow ServiceNow=washington_dc-patch_4
ServiceNow ServiceNow=washington_dc-patch_4_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_4_hotfix_1a
ServiceNow ServiceNow=washington_dc-patch_4_hotfix_1b
ServiceNow ServiceNow=washington_dc-patch_4_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_4_hotfix_2a
ServiceNow ServiceNow=washington_dc-patch_5
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_3
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_4
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_5
ServiceNow ServiceNow=washington_dc-patch_5_hotfix_6
ServiceNow ServiceNow=washington_dc-patch_6

Event History

Oct 29, 2024
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-8924?

CVE-2024-8924 is classified as a high severity vulnerability.

2

How do I fix CVE-2024-8924?

To fix CVE-2024-8924, ensure that your ServiceNow instance is updated to the latest version provided by ServiceNow.

3

What types of software are affected by CVE-2024-8924?

CVE-2024-8924 affects ServiceNow versions including xanadu and vancouver among others.

4

Can CVE-2024-8924 be exploited remotely?

Yes, CVE-2024-8924 can be exploited remotely by unauthenticated users.

5

What kind of data can be compromised due to CVE-2024-8924?

CVE-2024-8924 allows attackers to extract unauthorized information from the affected ServiceNow instances.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203