CVE-2024-8924
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1005Data from Local Systemcollection90 % - Impacto secundario
T1565.001Stored Data Manipulationimpact35 %
SQL injection ciega (CWE-89) en plataforma accesible sin autenticación (AV:N/PR:N/UI:N) permite extracción de datos no autorizada mediante T1190; manipulación de datos es especulativa.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-89
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-8924",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8924",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-30T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "psirt@servicenow.com",
"affectedData": [
{
"vendor": "ServiceNow",
"product": "Now Platform",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "Utah Patch 10b Hot Fix 3",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Vancouver Patch 8 Hot Fix 5",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Vancouver Patch 9 Hot Fix 3b",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Vancouver Patch 10 Hot Fix 2",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 4 Hot Fix 2b",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 5 Hot Fix 6",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 6 Hot Fix 1",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Washington DC Patch 7",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "Xanadu Patch 1",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:utah:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Utah",
"lessThan": "Utah Patch 10b Hot Fix 3",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:vancouver:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Vancouver",
"lessThan": "Vancouver Patch 8 Hot Fix 5",
"versionType": "custom"
},
{
"status": "affected",
"version": "Vancouver",
"lessThan": "Vancouver Patch 9 Hot Fix 3b",
"versionType": "custom"
},
{
"status": "affected",
"version": "Vancouver",
"lessThan": "Vancouver Patch 10 Hot Fix 2",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:washington_dc:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 4 Hot Fix 2b",
"versionType": "custom"
},
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 5 Hot Fix 6",
"versionType": "custom"
},
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 6 Hot Fix 1",
"versionType": "custom"
},
{
"status": "affected",
"version": "Washington_DC",
"lessThan": "Washington DC Patch 7",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:servicenow:servicenow:xanadu:*:*:*:*:*:*:*"
],
"vendor": "servicenow",
"product": "servicenow",
"versions": [
{
"status": "affected",
"version": "Xanadu",
"lessThan": "Xanadu Patch 1",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-10-29T17:15:04.983",
"references": [
{
"url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706072",
"tags": [
"Vendor Advisory"
],
"source": "psirt@servicenow.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@servicenow.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes."
},
{
"lang": "es",
"value": "ServiceNow ha solucionado una vulnerabilidad de inyección SQL ciega que se identificó en la plataforma Now. Esta vulnerabilidad podría permitir que un usuario no autenticado extraiga información no autorizada. ServiceNow implementó una actualización en las instancias alojadas y proporcionó la actualización a nuestros socios y clientes alojados por ellos mismos. Además, la vulnerabilidad se soluciona en los parches y correcciones urgentes que se indican."
}
],
"lastModified": "2026-06-17T08:23:34.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:xanadu:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7680E7D1-4508-4A4F-99B9-D7690052F185"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:xanadu:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D232F4B4-40DC-4251-92C9-F40D280AEE36"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:xanadu:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49E3A571-83E7-4168-ADF6-49AF92F68EC5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DB67FCA-6127-486F-A866-3D5E63B81C35"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8702C869-6136-4E0D-9C31-D3F23E9FFEB9"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B094239-6739-4E69-BFF6-7D2797024D8D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:early_availability_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D849F84-F4A9-4AF1-99B6-C57C34BDF4F8"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9132AB29-33C1-4825-BAD4-2804C26316B1"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_1_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68D99613-53A1-4B09-9A78-F8EFA0CC6B01"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E79B8B4-C9CF-4BD4-A634-6DB5EFCAA1FA"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_10_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B348587A-4407-4BC5-B4E0-207A283B66F6"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8FCCFB6-DB7E-4DED-A7E0-1C03087754F5"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7ED2051C-FE4F-4C0A-A3BF-E33141DC3250"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CFD4017-5B8E-4CAF-B9E5-4A675C11F01A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40D69E69-DF88-4F8C-A9BD-B642829107E4"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D21A542-15DC-432C-9C60-F7CABE8D4807"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1596163B-637A-49F9-B01F-C6CC297F7E5B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B915FDA-9DCB-43B5-8081-F0690996A3EF"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7308FA07-5C6D-41AA-9EE1-EE9BAAB50A1B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ED407E7-9595-4B4D-9D53-1A4807BA327C"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EA5B288-54DB-437E-88C2-05F90FF3C918"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6ED497ED-1588-4CF8-AE83-7CC7BEF8B982"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A74A3197-68F7-4303-A731-B87A8BF3F831"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A08FD0FD-E062-4BEC-BE95-0ED2D106826B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F6A6F12-4D7A-4FD3-8FD6-C32D797BB810"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "847F9124-F3C6-4C93-9E80-544CB0580C8C"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12808B52-8F7D-4EE0-A43E-85A1C70A6BE3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81880B84-5E9D-4B7F-B1D5-1BF8D25DAF5D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_5_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8011D2A7-770B-4AE5-80E6-C762F4F0BB55"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A58603E3-5AFC-4606-8F9E-1B4FF9A9B843"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BED5F42A-5FFF-43E0-9BAD-A5E6C1110551"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_6_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACC24566-0C5A-480D-AA79-19C5E9CE3D70"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ABE64339-EF0B-4430-9768-FA7DE82AA61F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF79CA67-765A-4CCB-B1CB-EE1FC02CFCFA"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3E71353-9AFF-4B6D-89BC-A2909A7C5DDF"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9C5B57E-7852-4E38-9BDA-864CF6F9DB5A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAA2E502-FCBC-404D-8FFA-4601F1D5B747"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "650956A6-8DE6-4C16-A77C-2B208B41DF5F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_3a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A49AC0E0-9164-43AD-959A-55FCB7965858"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_3b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24A4F6D1-2005-43CA-A282-6B532046CC60"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46277115-1A2B-4526-83E8-1446EB5A1EAB"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CDFB167-F252-46A6-A5F6-EF9A4F93FC03"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_1b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43DE243B-E90A-4857-A3A6-3A045FE2D75F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33689F99-48DD-47C6-AFAC-DC5D10785860"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotifix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F664F1F-5FB2-48B1-93C7-5DF415E673B7"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C641B881-7379-448A-A785-3381C72F8353"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03D48963-936B-4A48-8859-A5066A259E03"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9149B850-7196-476A-9A27-DEB85B8C6F19"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10622260-FCBC-4CC0-804E-55D75200FC46"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "629C9A33-02A6-459E-92F2-A815FFA5BC73"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28C0B816-2DE4-4314-8505-8A7F2EB6AE64"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF44F7A1-D153-4723-BA45-0FE4E4725C2F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9952FD7-E982-471E-933A-812FB24D7180"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5143ED1D-7B8A-4167-B76D-3946E9920E3B"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9517E3CB-3473-48B5-942A-E1AC215ECB6A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDB5D38B-DABC-4FD0-BE1F-6153E6209CE0"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:vancouver:patch_9_hotfix_3a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BF8DC1F-48AB-4BAD-83F5-2D370AB4E77C"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFAC3BF9-2443-4C43-B67A-2BB99297D295"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:early_availability:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84206FBF-9BE9-489C-AED6-522029D14091"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:early_availability_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02C383CA-F10F-44F1-9DAE-0CC6C049B83E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "444DD275-789F-4C07-9D98-BBFAA1640DB3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B29B708-BD7C-4A6C-9E78-37D045101A17"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F6EDFA3-9014-4AA7-A17F-DDB1FE96588E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DA447CA-A6A2-436C-9909-3F0419B7DD6F"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F263893-6D34-49D6-9407-ED6CB823595E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_3b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5BC2E0F-21A6-4AA2-8B4D-C7DEE1D34FC7"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D18E2CD1-AC8E-4ABF-88DE-D3E61A297ED1"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52FC3724-35E5-4C3A-B6BA-3B270EA4255E"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D663C66D-460F-417E-BC40-D2F0D64246BD"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6137BB81-6B48-4DCB-A9F6-A27D869C12FC"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B06EABB5-0327-4816-AC7B-34D021758812"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AE9E970-A457-4D7F-91F0-B7A0956C4115"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E117698-641B-4A61-A0A1-5360A6A47EC3"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29DC5FC9-2ACF-4C51-93C4-2D0982BA0CA6"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F527AEBC-C859-45A2-B9A3-B627B99430AC"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_1a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "866088B4-F98B-4C76-BE9C-01505DCA0422"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_1b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84A86B15-85A4-43B0-A848-F6BDE6F925D6"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA24D4D4-9531-4A39-82AB-C559AD956821"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_4_hotfix_2a:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E038E7CE-F29B-4684-A20A-BD564C2F72D0"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9CD5A918-9B71-4CFD-A6DB-437D3B647C6A"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8CB6895-5EA1-4D97-B563-ED192B4ADA3D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17D05A6C-5B6B-4DF0-A2A6-D23C05B55FB7"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2514E534-4160-4B28-B4B3-FF8DDDE6F7F2"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4533B128-E765-4542-938F-5CF254249C15"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98E4AFA9-6551-4D22-AFB1-666936DC311D"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_5_hotfix_6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F72D90CB-C5EB-4F03-B320-0ACF9397C724"
},
{
"criteria": "cpe:2.3:a:servicenow:servicenow:washington_dc:patch_6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA936070-C32B-4539-A14F-1F6965A01107"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@servicenow.com"
}