CVE-2024-8923
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.11%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 %
Vector AV:N/PR:N/UI:N indica acceso remoto sin autenticación; CWE-94 es ejecución de código; descripción explícita de RCE remota sin autenticación.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-8923",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8923",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-30T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "psirt@servicenow.com",
"affectedData": [
{
"vendor": "ServiceNow",
"product": "Now Platform",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "Vancouver Patch 9 Hot Fix 2a",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Vancouver Patch 10",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 4 Hot Fix 1a",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 5",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Xanadu GA Release",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:vancouver:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Vancouver",
"lessThan": "Vancouver Patch 9 Hot Fix 2a",
"versionType": "custom"
},
{
"status": "affected",
"version": "Vancouver",
"lessThan": "Vancouver Patch 10",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:washington_dc:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 4 Hot Fix 1a",
"versionType": "custom"
},
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 5",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:xanadu:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Xanadu",
"lessThan": "Xanadu GA Release",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-10-29T16:15:06.417",
"references": [
{
"url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706070",
"tags": [
"Vendor Advisory"
],
"source": "psirt@servicenow.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes."
},
{
"lang": "es",
"value": " ServiceNow ha solucionado una vulnerabilidad de validación de entrada que se identificó en Now Platform. Esta vulnerabilidad podría permitir que un usuario no autenticado ejecute código de forma remota dentro del contexto de Now Platform. ServiceNow implementó una actualización en las instancias alojadas y proporcionó la actualización a nuestros socios y clientes alojados por ellos mismos. Además, la vulnerabilidad se soluciona en los parches y correcciones urgentes que se indican."
}
],
"lastModified": "2026-06-17T08:23:34.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:xanadu:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D232F4B4-40DC-4251-92C9-F40D280AEE36"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:xanadu:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49E3A571-83E7-4168-ADF6-49AF92F68EC5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFAC3BF9-2443-4C43-B67A-2BB99297D295"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84206FBF-9BE9-489C-AED6-522029D14091"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02C383CA-F10F-44F1-9DAE-0CC6C049B83E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "444DD275-789F-4C07-9D98-BBFAA1640DB3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B29B708-BD7C-4A6C-9E78-37D045101A17"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F6EDFA3-9014-4AA7-A17F-DDB1FE96588E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DA447CA-A6A2-436C-9909-3F0419B7DD6F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F263893-6D34-49D6-9407-ED6CB823595E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_3b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5BC2E0F-21A6-4AA2-8B4D-C7DEE1D34FC7"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D18E2CD1-AC8E-4ABF-88DE-D3E61A297ED1"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52FC3724-35E5-4C3A-B6BA-3B270EA4255E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D663C66D-460F-417E-BC40-D2F0D64246BD"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6137BB81-6B48-4DCB-A9F6-A27D869C12FC"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B06EABB5-0327-4816-AC7B-34D021758812"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AE9E970-A457-4D7F-91F0-B7A0956C4115"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E117698-641B-4A61-A0A1-5360A6A47EC3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29DC5FC9-2ACF-4C51-93C4-2D0982BA0CA6"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F527AEBC-C859-45A2-B9A3-B627B99430AC"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DB67FCA-6127-486F-A866-3D5E63B81C35"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8702C869-6136-4E0D-9C31-D3F23E9FFEB9"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B094239-6739-4E69-BFF6-7D2797024D8D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D849F84-F4A9-4AF1-99B6-C57C34BDF4F8"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9132AB29-33C1-4825-BAD4-2804C26316B1"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_1_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68D99613-53A1-4B09-9A78-F8EFA0CC6B01"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8FCCFB6-DB7E-4DED-A7E0-1C03087754F5"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7ED2051C-FE4F-4C0A-A3BF-E33141DC3250"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CFD4017-5B8E-4CAF-B9E5-4A675C11F01A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40D69E69-DF88-4F8C-A9BD-B642829107E4"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D21A542-15DC-432C-9C60-F7CABE8D4807"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1596163B-637A-49F9-B01F-C6CC297F7E5B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B915FDA-9DCB-43B5-8081-F0690996A3EF"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7308FA07-5C6D-41AA-9EE1-EE9BAAB50A1B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ED407E7-9595-4B4D-9D53-1A4807BA327C"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EA5B288-54DB-437E-88C2-05F90FF3C918"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6ED497ED-1588-4CF8-AE83-7CC7BEF8B982"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A74A3197-68F7-4303-A731-B87A8BF3F831"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A08FD0FD-E062-4BEC-BE95-0ED2D106826B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F6A6F12-4D7A-4FD3-8FD6-C32D797BB810"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "847F9124-F3C6-4C93-9E80-544CB0580C8C"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12808B52-8F7D-4EE0-A43E-85A1C70A6BE3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81880B84-5E9D-4B7F-B1D5-1BF8D25DAF5D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_5_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8011D2A7-770B-4AE5-80E6-C762F4F0BB55"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A58603E3-5AFC-4606-8F9E-1B4FF9A9B843"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BED5F42A-5FFF-43E0-9BAD-A5E6C1110551"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACC24566-0C5A-480D-AA79-19C5E9CE3D70"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE64339-EF0B-4430-9768-FA7DE82AA61F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF79CA67-765A-4CCB-B1CB-EE1FC02CFCFA"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3E71353-9AFF-4B6D-89BC-A2909A7C5DDF"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9C5B57E-7852-4E38-9BDA-864CF6F9DB5A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAA2E502-FCBC-404D-8FFA-4601F1D5B747"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "650956A6-8DE6-4C16-A77C-2B208B41DF5F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_3a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A49AC0E0-9164-43AD-959A-55FCB7965858"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_3b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24A4F6D1-2005-43CA-A282-6B532046CC60"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46277115-1A2B-4526-83E8-1446EB5A1EAB"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CDFB167-F252-46A6-A5F6-EF9A4F93FC03"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_1b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43DE243B-E90A-4857-A3A6-3A045FE2D75F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33689F99-48DD-47C6-AFAC-DC5D10785860"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F664F1F-5FB2-48B1-93C7-5DF415E673B7"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C641B881-7379-448A-A785-3381C72F8353"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03D48963-936B-4A48-8859-A5066A259E03"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9149B850-7196-476A-9A27-DEB85B8C6F19"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10622260-FCBC-4CC0-804E-55D75200FC46"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "629C9A33-02A6-459E-92F2-A815FFA5BC73"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28C0B816-2DE4-4314-8505-8A7F2EB6AE64"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF44F7A1-D153-4723-BA45-0FE4E4725C2F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9952FD7-E982-471E-933A-812FB24D7180"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5143ED1D-7B8A-4167-B76D-3946E9920E3B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@servicenow.com"
}