← ServiceNow

2025 ServiceNow — CVE-2025-3648 ‘Counter Strike’ data-inference exposure class (Varonis research)

2025 Unknown records affected Share on X

Data compromised

Fields inferable from poorly restricted record-count UI patterns in affected instances

Technical writeup

Varonis disclosed a UI inference weakness in common ServiceNow configurations that could reveal record content via counters when ACLs were insufficiently strict; vendors and customers issued patching and hardening guidance.

Root cause

Information disclosure via predictable UI inference patterns in platform configurations

References