• News/
  • https://www.bleepingcomputer.com/news/security/new-servicenow-flaw-lets-attackers-enumerate-restricted-data/

New ServiceNow flaw lets attackers enumerate restricted data

BleepingComputer
·
Lawrence Abrams
·
Published Jul 9, 2025
·
Updated

A new vulnerability in ServiceNow, dubbed Count(er) Strike, allows low-privileged users to extract sensitive data from tables to which they should not have access. ServiceNow is a cloud-based platform that enables organizations to manage digital workflows for their enterprise operations. It is widely adopted across various industries, including public sector organizations, healthcare, financial institutions, and large enterprises. The flaw was discovered by Varonis Threat Labs in February 2024 and assigned the CVE-2025-3648 identifier, and may impact configurations with misconfigured or overly permissive ACLs. ServiceNow released additional access control frameworks in the Xanadu and Yokohama versions, released last month, to address the issue. However, all admins should review existing tables to ensure their data is properly locked down. ServiceNow utilizes Access Control Lists (ACLs) to restrict access to data within its tables. Each ACL evaluates four conditions when determining if a user should have access to a specific resource: For a user to gain access to a resource, all of these conditions must be satisfied. However, if a resource is protected with multiple ACLs, ServiceNow previously used an "Allow if" condition, meaning that if a user satisfied just one ACL, they could gain access, even if other ACLs would have blocked them. In some cases, this granted full access. However, in others, it allowed partial access, such as record counts that could be exploited, as expl...

Read full article

Affected Software

2 affected components
ServiceNow ServiceNow=Xanadu
ServiceNow ServiceNow=Yokohama
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new vulnerability in ServiceNow that allows low-privileged users to access restricted data.

2

What security implications are discussed?

The vulnerability could lead to unauthorized access to sensitive information within ServiceNow, impacting data privacy and security.

3

What products or software are affected?

The flaw affects the ServiceNow platform, which manages digital workflows for organizations.

4

What is the name of the vulnerability mentioned in the article?

The vulnerability is referred to as Count(er) Strike.

5

Who is impacted by this ServiceNow vulnerability?

Low-privileged users on the ServiceNow platform are primarily impacted as they can exploit the flaw to extract sensitive data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203