CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0337: Authorization bypass in Now Platform

7.1 CVSS

Description

ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable an authenticated user to access unauthorized data stored within the Now Platform that the user otherwise would not be entitled to access.

This issue is addressed in the listed patches and family release, which have been made available to hosted and self-hosted customers, as well as partners.

Classification

CVE ID: CVE-2025-0337

CVSS Base Severity: HIGH

CVSS Base Score: 7.1

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem Types

CWE-639 Authorization Bypass Through User-Controlled Key

Affected Products

Vendor: ServiceNow

Product: Now Platform

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 4.97% (scored less or equal to compared to others)

EPSS Date: 2025-04-04 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2025-0337
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1948695

Timeline