Worrying ServiceNow security flaw could let hackers steal private table data




  • A mishap in ServiceNow access control lists meant users could be granted access, without meeting all the conditions
  • New controls were added to mitigate the risk
  • Users are advised to review their tables and ACLs

A flaw in ServiceNow could have allowed threat actors to exfiltrate sensitive data from other user’s tables without them ever knowing, security experts have warned.

The flaw, tracked as CVE-2025-3648 and given a severity score of 8.2/10 (high), was dubbed “Count(er) Strike”, and was spotted by security researchers Varonis.

https://cdn.mos.cms.futurecdn.net/bLTg6GBXmrv6c5v7AJFPsT.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img