Answer in brief
CVE-2024-5217 records a High severity vulnerability in Incomplete Input Validation in GlideExpression Script. The current sources mark it as known exploited. The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/Now Platformgeneric | >=0 <Utah Patch 10 Hot Fix 3 || >=0 <Utah Patch 10a Hot Fix 2 || >=0 <Utah Patch 10b Hot Fix 1 || >=0 <Vancouver Patch 6 Hot Fix 2 || >=0 <Vancouver Patch 7 Hot Fix 3b || >=0 <Vancouver Patch 8 Hot Fix 4 || >=0 <Vancouver Patch 9 Hot Fix 1 || >=0 <Vancouver Patch 10 || >=0 <Washington DC Patch 1 Hot Fix 3b || >=0 <Washington DC Patch 2 Hot Fix 2 || >=0 <Washington DC Patch 3 Hot Fix 2 || >=0 <Washington DC Patch 4 || >=0 <Washington DC Patch 5 | Utah Patch 10 Hot Fix 3, Utah Patch 10a Hot Fix 2, Utah Patch 10b Hot Fix 1, Vancouver Patch 6 Hot Fix 2, Vancouver Patch 7 Hot Fix 3b, Vancouver Patch 8 Hot Fix 4, Vancouver Patch 9 Hot Fix 1, Vancouver Patch 10, Washington DC Patch 1 Hot Fix 3b, Washington DC Patch 2 Hot Fix 2, Washington DC Patch 3 Hot Fix 2, Washington DC Patch 4, Washington DC Patch 5 |
| servicenow/servicenowgeneric | >=0 <utah_patch_10_hot_fix_3 || >=0 <utah_patch_10a_hot_fix_2 || >=0 <utah_patch_10b_hot_fix_1 || >=0 <vancouver_patch_6_hot_fix_2 || >=0 <vancouver_patch_7_hot_fix_3b || >=0 <vancouver_patch_8_hot_fix_4 || >=0 <vancouver_patch_9_hot_fix_1 || >=0 <vancouver_patch_10 || >=0 <washington_dc_patch_1_hot_fix_3b || >=0 <washington_dc_patch_2_hot_fix_2 || >=0 <washington_dc_patch_3_hot_fix_2 || >=0 <washington_dc_patch_4 || >=0 <washington_dc_patch_5 | utah_patch_10_hot_fix_3, utah_patch_10a_hot_fix_2, utah_patch_10b_hot_fix_1, vancouver_patch_6_hot_fix_2, vancouver_patch_7_hot_fix_3b, vancouver_patch_8_hot_fix_4, vancouver_patch_9_hot_fix_1, vancouver_patch_10, washington_dc_patch_1_hot_fix_3b, washington_dc_patch_2_hot_fix_2, washington_dc_patch_3_hot_fix_2, washington_dc_patch_4, washington_dc_patch_5 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Jul 29, 2024
Evidence: source:kev:kev:kev:recordServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-5217 records a High severity vulnerability in Incomplete Input Validation in GlideExpression Script. The current sources mark it as known exploited. The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/Now Platformgeneric | >=0 <Utah Patch 10 Hot Fix 3 || >=0 <Utah Patch 10a Hot Fix 2 || >=0 <Utah Patch 10b Hot Fix 1 || >=0 <Vancouver Patch 6 Hot Fix 2 || >=0 <Vancouver Patch 7 Hot Fix 3b || >=0 <Vancouver Patch 8 Hot Fix 4 || >=0 <Vancouver Patch 9 Hot Fix 1 || >=0 <Vancouver Patch 10 || >=0 <Washington DC Patch 1 Hot Fix 3b || >=0 <Washington DC Patch 2 Hot Fix 2 || >=0 <Washington DC Patch 3 Hot Fix 2 || >=0 <Washington DC Patch 4 || >=0 <Washington DC Patch 5 | Utah Patch 10 Hot Fix 3, Utah Patch 10a Hot Fix 2, Utah Patch 10b Hot Fix 1, Vancouver Patch 6 Hot Fix 2, Vancouver Patch 7 Hot Fix 3b, Vancouver Patch 8 Hot Fix 4, Vancouver Patch 9 Hot Fix 1, Vancouver Patch 10, Washington DC Patch 1 Hot Fix 3b, Washington DC Patch 2 Hot Fix 2, Washington DC Patch 3 Hot Fix 2, Washington DC Patch 4, Washington DC Patch 5 |
| servicenow/servicenowgeneric | >=0 <utah_patch_10_hot_fix_3 || >=0 <utah_patch_10a_hot_fix_2 || >=0 <utah_patch_10b_hot_fix_1 || >=0 <vancouver_patch_6_hot_fix_2 || >=0 <vancouver_patch_7_hot_fix_3b || >=0 <vancouver_patch_8_hot_fix_4 || >=0 <vancouver_patch_9_hot_fix_1 || >=0 <vancouver_patch_10 || >=0 <washington_dc_patch_1_hot_fix_3b || >=0 <washington_dc_patch_2_hot_fix_2 || >=0 <washington_dc_patch_3_hot_fix_2 || >=0 <washington_dc_patch_4 || >=0 <washington_dc_patch_5 | utah_patch_10_hot_fix_3, utah_patch_10a_hot_fix_2, utah_patch_10b_hot_fix_1, vancouver_patch_6_hot_fix_2, vancouver_patch_7_hot_fix_3b, vancouver_patch_8_hot_fix_4, vancouver_patch_9_hot_fix_1, vancouver_patch_10, washington_dc_patch_1_hot_fix_3b, washington_dc_patch_2_hot_fix_2, washington_dc_patch_3_hot_fix_2, washington_dc_patch_4, washington_dc_patch_5 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Jul 29, 2024
Evidence: source:kev:kev:kev:recordServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
Quoted source text, attributed separately from HOL analysis.