ServiceNow Remote Code Execution Attack
ID: 03b5c69f-1372-5456-a30f-5e24bca2d888
STIX ID: report--03b5c69f-1372-5456-a30f-5e24bca2d888
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
FortiGuard Labs reports active attack attempts against three ServiceNow Now Platform vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) — including Jelly Template Injection and incomplete input validation bugs that can enable remote code execution and unauthorized access. The flaws affect multiple Now Platform releases, are reportedly being targeted in the wild with potential PoC weaponization, and organizations using ServiceNow are advised to apply the vendor updates immediately to mitigate potential data breaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
