Worrying ServiceNow security flaw could let hackers steal private table data




  • A mishap in ServiceNow access control lists meant users could be granted access, without meeting all the conditions
  • New controls were added to mitigate the risk
  • Users are advised to review their tables and ACLs

A flaw in ServiceNow could have allowed threat actors to exfiltrate sensitive data from other user’s tables without them ever knowing, security experts have warned.

The flaw, tracked as CVE-2025-3648 and given a severity score of 8.2/10 (high), was dubbed “Count(er) Strike”, and was spotted by security researchers Varonis.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *