Evidence dossier

CVE-2024-4879

Jelly Template Injection Vulnerability in ServiceNow UI Macros

Exploited in the wild (CISA KEV since Jul 29, 2024). SN reports CVSS 4.0 9.3. EPSS estimates 100.0% exploit likelihood as of Aug 4, 2026.

85.993.3Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

State
PUBLISHED
Published
Jul 10, 2024
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    SN

    Record text: Jelly Template Injection Vulnerability in ServiceNow UI Macros

    Inspect raw assertion
    Field
    container
    Value
    Jelly Template Injection Vulnerability in ServiceNow UI Macros
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: ServiceNow Improper Input Validation Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    ServiceNow Improper Input Validation Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.98% probability · 99.98th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999760000000; percentile 0.999790000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jul 29, 2024 · first observed Jul 19, 2026

Exploit likelihood99.98%

FIRST EPSS · score date Aug 4, 2026 · 100th percentile · first observed Aug 4, 2026

SeverityCVSS 9.3

SN · CVSS 4.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
SNOriginal assertion
Record text

Jelly Template Injection Vulnerability in ServiceNow UI Macros

Inspect raw assertion
Field
container
Value
Jelly Template Injection Vulnerability in ServiceNow UI Macros
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

ServiceNow Improper Input Validation Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
ServiceNow Improper Input Validation Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.98% probability · 99.98th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999760000000; percentile 0.999790000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
90Underlying assertions
1Canonical products
90Target assertions
0Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

13 scope groups

CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
CISA-ADP · source assertedservicenowservicenowDirect source scope
Affected: 0 to before utah_patch_10_hot_fix_3 (custom comparison)Affected: 0 to before utah_patch_10a_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_6_hot_fix_2 (custom comparison)Affected: 0 to before vancouver_patch_7_hot_fix_3b (custom comparison)Affected: 0 to before vancouver_patch_8_hot_fix_4 (custom comparison)Affected: 0 to before vancouver_patch_9 (custom comparison)Affected: 0 to before vancouver_patch_10 (custom comparison)Affected: 0 to before washington_dc_patch_1_hot_fix_2b (custom comparison)Affected: 0 to before washington_dc_patch_2_hot_fix_2 (custom comparison)Affected: 0 to before washington_dc_patch_3_hot_fix_1 (custom comparison)Affected: 0 to before washington_dc_patch_4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "utah_patch_10_hot_fix_3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "utah_patch_10a_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_6_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_7_hot_fix_3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_8_hot_fix_4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "vancouver_patch_10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_1_hot_fix_2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_2_hot_fix_2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_3_hot_fix_1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "washington_dc_patch_4", "versionType": "custom"}]
SN · source assertedServiceNowNow PlatformDirect source scope
Affected: 0 to before Utah Patch 10 Hot Fix 3 (custom comparison)Affected: 0 to before Utah Patch 10a Hot Fix 2 (custom comparison)Affected: 0 to before Vancouver Patch 6 Hot Fix 2 (custom comparison)Affected: 0 to before Vancouver Patch 7 Hot Fix 3b (custom comparison)Affected: 0 to before Vancouver Patch 8 Hot Fix 4 (custom comparison)Affected: 0 to before Vancouver Patch 9 (custom comparison)Affected: 0 to before Vancouver Patch 10 (custom comparison)Affected: 0 to before Washington DC Patch 1 Hot Fix 2b (custom comparison)Affected: 0 to before Washington DC Patch 2 Hot Fix 2 (custom comparison)Affected: 0 to before Washington DC Patch 3 Hot Fix 1 (custom comparison)Affected: 0 to before Washington DC Patch 4 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "lessThan": "Utah Patch 10 Hot Fix 3", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Utah Patch 10a Hot Fix 2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Vancouver Patch 6 Hot Fix 2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Vancouver Patch 7 Hot Fix 3b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Vancouver Patch 8 Hot Fix 4", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Vancouver Patch 9", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Vancouver Patch 10", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Washington DC Patch 1 Hot Fix 2b", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Washington DC Patch 2 Hot Fix 2", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Washington DC Patch 3 Hot Fix 1", "versionType": "custom"}, {"status": "affected", "version": "0", "lessThan": "Washington DC Patch 4", "versionType": "custom"}]
NVD CPE · APPLICATIONservicenowservicenowVulnerable target · 90 assertions
Version utah; Version vancouver; Version washington_dcCanonical identity product-53ca0a2ec8b8d1656216c47fc947cd376bcf16d5b3955539bd2439e41094ba8cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7308fa07-5c6d-41aa-9ee1-ee9baab50a1b
  2. cpe:2.3:a:servicenow:servicenow:utah:patch_7a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f601f74-593a-4566-a763-ef05e5138fa7
  3. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    402d816a-2650-4743-a386-029c0d063c39
  4. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eaa2e502-fcbc-404d-8ffa-4601f1d5b747
  5. cpe:2.3:a:servicenow:servicenow:utah:patch_10a_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eebb1dce-25aa-4f95-984c-5bb5341a90ed
  6. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56cbe65e-2d5a-4191-a2f4-8ac76050404f
  7. cpe:2.3:a:servicenow:servicenow:utah:patch_1_hotfix_1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a76b918-45db-49a9-b323-5cb6ff8200aa
  8. cpe:2.3:a:servicenow:servicenow:utah:patch_6_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aadfd5ce-9c9d-46ff-9871-e2bd7b2c8b98
  9. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40d69e69-df88-4f8c-a9bd-b642829107e4
  10. cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6ed497ed-1588-4cf8-ae83-7cc7bef8b982
  11. cpe:2.3:a:servicenow:servicenow:utah:patch_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d6885dd-230b-468b-b936-7512be80849d
  12. cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_2b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    12808b52-8f7d-4ee0-a43e-85a1c70a6be3
  13. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0ec8ace-70ca-44fc-aca7-0868d620c86d
  14. cpe:2.3:a:servicenow:servicenow:utah:patch_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d934721-565f-4707-a32a-b7e4bb9d2dd0
  15. cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ea5b288-54db-437e-88c2-05f90ff3c918
  16. cpe:2.3:a:servicenow:servicenow:utah:patch_9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    26d23ee3-0f88-47f7-adcd-b74f81a08d9b
  17. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1596163b-637a-49f9-b01f-c6cc297f7e5b
  18. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_3b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    996c57b4-e8ac-48f6-ba71-328f714b1bac
  19. cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f6a6f12-4d7a-4fd3-8fd6-c32d797bb810
  20. cpe:2.3:a:servicenow:servicenow:utah:patch_9_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb793686-954a-49f8-bc35-a95325d61303
  21. cpe:2.3:a:servicenow:servicenow:utah:patch_1_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44506775-0370-4583-9236-6c9f646b6622
  22. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    650956a6-8de6-4c16-a77c-2b208b41df5f
  23. cpe:2.3:a:servicenow:servicenow:utah:patch_10_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8097d9b0-9329-4eb7-bb7e-0ff3057d408b
  24. cpe:2.3:a:servicenow:servicenow:vancouver:patch_6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a58603e3-5afc-4606-8f9e-1b4ff9a9b843
  25. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_4b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d66b18d1-486d-4390-9d1e-5348d1c6729a
  26. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_2b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    76d69b8d-02ee-4e3d-9f54-e94f6db09d5b
  27. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    444dd275-789f-4c07-9d98-bbfaa1640db3
  28. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cc772dd6-2814-4eef-a524-cc752c277337
  29. cpe:2.3:a:servicenow:servicenow:vancouver:patch_1_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    68d99613-53a1-4b09-9a78-f8efa0cc6b01
  30. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d18e2cd1-ac8e-4abf-88de-d3e61a297ed1
  31. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1f6edfa3-9014-4aa7-a17f-ddb1fe96588e
  32. cpe:2.3:a:servicenow:servicenow:utah:patch_7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8bd49264-d243-4625-828c-af383d826779
  33. cpe:2.3:a:servicenow:servicenow:utah:patch_8_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    24d2ebc6-f894-4c1d-a2ff-b49ff4007ed8
  34. cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    10622260-fcbc-4cc0-804e-55d75200fc46
  35. cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    03d48963-936b-4a48-8859-a5066a259e03
  36. cpe:2.3:a:servicenow:servicenow:washington_dc:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffac3bf9-2443-4c43-b67a-2bb99297d295
  37. cpe:2.3:a:servicenow:servicenow:vancouver:patch_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0b915fda-9dcb-43b5-8081-f0690996a3ef
  38. cpe:2.3:a:servicenow:servicenow:utah:patch_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    98e3e0af-a341-43bb-91c6-75bbde695280
  39. cpe:2.3:a:servicenow:servicenow:utah:patch_7b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    47d4cc0e-e3f5-49ab-9d92-ac8ffb17a4c0
  40. cpe:2.3:a:servicenow:servicenow:vancouver:patch_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9132ab29-33c1-4825-bad4-2804c26316b1
  41. cpe:2.3:a:servicenow:servicenow:utah:patch_7_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac4ca2b8-efd8-4c01-8f9c-e613619062df
  42. cpe:2.3:a:servicenow:servicenow:utah:patch_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    481ec1aa-5863-4641-b67f-cd51416ed0ea
  43. cpe:2.3:a:servicenow:servicenow:utah:early_availability:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    03fe0b52-c7a6-4632-a09e-be7ab8610dd7
  44. cpe:2.3:a:servicenow:servicenow:utah:patch_6_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ece96eed-c729-4a84-b437-79cce029c391
  45. cpe:2.3:a:servicenow:servicenow:utah:patch_10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    76439fc6-2dd2-4ad4-9eb6-a2feac10b205
  46. cpe:2.3:a:servicenow:servicenow:utah:patch_5_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4aa97d74-290c-47c7-9976-6ef83950c530
  47. cpe:2.3:a:servicenow:servicenow:vancouver:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9db67fca-6127-486f-a866-3d5e63b81c35
  48. cpe:2.3:a:servicenow:servicenow:vancouver:patch_5_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8011d2a7-770b-4ae5-80e6-c762f4f0bb55
  49. cpe:2.3:a:servicenow:servicenow:utah:patch_10_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    afea8d14-d1c8-486b-abe7-25c9d6b72ce9
  50. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6137bb81-6b48-4dcb-a9f6-a27d869c12fc
  51. cpe:2.3:a:servicenow:servicenow:utah:patch_6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    122e0c17-b29b-44b9-a37e-745b103ad398
  52. cpe:2.3:a:servicenow:servicenow:vancouver:patch_5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    81880b84-5e9d-4b7f-b1d5-1bf8d25daf5d
  53. cpe:2.3:a:servicenow:servicenow:utah:patch_9_hotfix_1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    38ddaca8-69a9-4047-ad99-a7ddc320ead8
  54. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5b29b708-bd7c-4a6c-9e78-37d045101a17
  55. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_1_hotfix_2a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1da447ca-a6a2-436c-9909-3f0419b7dd6f
  56. cpe:2.3:a:servicenow:servicenow:utah:patch_7_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb29fcec-3ddb-46ee-a7aa-4728e6b9a1d6
  57. cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a08fd0fd-e062-4bec-be95-0ed2d106826b
  58. cpe:2.3:a:servicenow:servicenow:utah:patch_10a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5da716a2-e697-4bc3-8127-e772e67e1c49
  59. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8cfd4017-5b8e-4caf-b9e5-4a675c11f01a
  60. cpe:2.3:a:servicenow:servicenow:vancouver:patch_8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c641b881-7379-448a-a785-3381c72f8353
  61. cpe:2.3:a:servicenow:servicenow:utah:patch_1_hotfix_1b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    118b4618-8702-4c38-88ee-b41c2c9dbf31
  62. cpe:2.3:a:servicenow:servicenow:utah:patch_3_hotfix_1b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9783ca53-cdbd-44f0-b2b9-8c49ebe9fcb4
  63. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_2a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    05587bc2-574f-42b6-a121-7acfd0691ed5
  64. cpe:2.3:a:servicenow:servicenow:vancouver:patch_10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7e79b8b4-c9cf-4bd4-a634-6db5efcaa1fa
  65. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3e71353-9aff-4b6d-89bc-a2909a7c5ddf
  66. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8fccfb6-db7e-4ded-a7e0-1c03087754f5
  67. cpe:2.3:a:servicenow:servicenow:vancouver:patch_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a74a3197-68f7-4303-a731-b87a8bf3f831
  68. cpe:2.3:a:servicenow:servicenow:utah:patch_8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8a4cd267-d72a-4f09-be9b-f008b1804ad9
  69. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d21a542-15dc-432c-9c60-f7cabe8d4807
  70. cpe:2.3:a:servicenow:servicenow:utah:patch_1_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    92bed123-0ffc-4113-b0b6-a1a8bd69f4cf
  71. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9c5b57e-7852-4e38-9bda-864cf6f9db5a
  72. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_3a:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a49ac0e0-9164-43ad-959a-55fcb7965858
  73. cpe:2.3:a:servicenow:servicenow:vancouver:patch_3_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ed407e7-9595-4b4d-9d53-1a4807ba327c
  74. cpe:2.3:a:servicenow:servicenow:vancouver:patch_2_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ed2051c-fe4f-4c0a-a3bf-e33141dc3250
  75. cpe:2.3:a:servicenow:servicenow:vancouver:patch_9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf44f7a1-d153-4723-ba45-0fe4e4725c2f
  76. cpe:2.3:a:servicenow:servicenow:utah:patch_2_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44f86beb-77d0-41af-816c-f73b2d9601fe
  77. cpe:2.3:a:servicenow:servicenow:utah:patch_3_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1476c240-fcb0-43e3-9c79-2264db6c200a
  78. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    abe64339-ef0b-4430-9768-fa7de82aa61f
  79. cpe:2.3:a:servicenow:servicenow:utah:patch_9_hotfix_1b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    926c0f6a-0599-4239-b1ce-5d864bbaa315
  80. cpe:2.3:a:servicenow:servicenow:vancouver:patch_6_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bed5f42a-5fff-43e0-9bad-a5e6c1110551
  81. cpe:2.3:a:servicenow:servicenow:utah:patch_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db5ca109-5dc1-4952-ac15-69fac332bca2
  82. cpe:2.3:a:servicenow:servicenow:utah:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69e0078e-1953-4f4f-9d5a-b1a140c4b310
  83. cpe:2.3:a:servicenow:servicenow:utah:patch_2_hotfix_3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9c467aa-b1a2-4a2a-8363-623232bcbca0
  84. cpe:2.3:a:servicenow:servicenow:washington_dc:patch_2_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52fc3724-35e5-4c3a-b6ba-3b270ea4255e
  85. cpe:2.3:a:servicenow:servicenow:vancouver:patch_4_hotfix_1b:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    847f9124-f3c6-4c93-9e80-544cb0580c8c
  86. cpe:2.3:a:servicenow:servicenow:vancouver:patch_8_hotfix_2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9149b850-7196-476a-9a27-deb85b8c6f19
  87. cpe:2.3:a:servicenow:servicenow:utah:patch_4_hotfix_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    10b82be2-be38-4ea7-85d5-ac28ff4f50bd
  88. cpe:2.3:a:servicenow:servicenow:vancouver:patch_7_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ff79ca67-765a-4ccb-b1cb-ee1fc02cfcfa
  89. cpe:2.3:a:servicenow:servicenow:utah:patch_2_hotfix_4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6e189f6-6623-4a0c-8767-a3cc1c12b759
  90. cpe:2.3:a:servicenow:servicenow:utah:patch_2_hotfix_1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    20ac3991-0e5b-4164-807f-0e270b1867be

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
psirt@servicenow.comCVSS 4.0 · role Secondary · priority eligiblevalid_matchCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9.8
psirt@servicenow.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
SNCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8
SNCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.