A new flaw has been found in ServiceNow, dubbed Count(er) Strike, which allows users with limited privileges to extract sensitive data from tables they shouldn't have access to.
See also: SAP fixes critical remote code execution flaws

ServiceNow is a cloud-based platform that enables organizations to manage digital workflows for their business operations. It is widely used in various sectors, such as the public sector, healthcare, financial institutions , and large enterprises.
The ServiceNow flaw, identified by Varonis Threat Labs in February 2025 and assigned the identifier CVE-2025-3648, may affect systems with incorrectly configured or overly permissive ACLs (Access Control Lists). ServiceNow has released additional access control mechanisms in its Xanadu and Yokohama, released last month, to address the issue. However, all administrators are advised to review their existing tables and ensure that their data is properly protected.
ServiceNow uses ACLs to restrict access to data within its tables. Each ACL evaluates four conditions to decide whether a user should have access to a particular resource:
- Required roles
- Security attributes
- Data conditions
- Scenario conditions (script)
See also: Exploits for NetScaler's CitrixBleed2 flaw released publicly
For a user to access the resources, all of these conditions must be met.

However, if a resource is protected by multiple ACLs, ServiceNow previously used an “Allow if” logic , which meant that if the user satisfied just one of the ACLs, they were allowed access — even if the remaining ACLs blocked them.
In some cases, this led to full access, while in others it allowed partial access, such as viewing record counts, which could be exploited maliciously.
This permissive model led Varonis to discover that partial access could be obtained, which could be leveraged for counting and locating protected data, even if the user did not comply with stricter ACL rules.
Varonis found that if a user fails to pass the data or script condition, ServiceNow still displays the record count in both the UI and the HTML of the page. The page itself also displays a message that some results have been removed due to security restrictions.
See also: Over 46,000 Grafana installations vulnerable to flaw
Varonis warned that even users who have registered themselves through self-registration can exploit this vulnerability. The self-registration allows users to create accounts and access the platform with minimal privileges — which, however, are enough to launch such an attack.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
