Improper access control in ServiceNow - CVE-2025-3648
Published: July 9, 2025
ServiceNow
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to sensitive information.
How to mitigate CVE-2025-3648
Install updates from vendor's website.
Note, it is unclear, in which versions of ServiceNow the vulnerability was fixed.