Count(er) Strike: CVE-2025-3648 Exposes ServiceNow Data

Amber | Vulnerability Report
Download PDF

CVE-2025-3648, codenamed “Count(er) Strike,” is a high-severity flaw in the ServiceNow platform that lets attackers, even without full access, quietly piece together sensitive information like user data or internal configurations. The issue lies in how ServiceNow handles certain access controls under specific conditions, it unintentionally reveals how many records match a search, even if users aren’t allowed to see the data itself. By using clever filter tricks, attackers can slowly infer restricted details, character by character. While no active attacks have been reported yet, the vulnerability is easy to exploit, making it crucial for organizations to update ServiceNow and review their ACL settings right away.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs