nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-0337 CVE-2025-0337
HIGH
Authorization bypass in Now Platform
Record summary
CVE-2025-0337 has a selected CVSS score of 7.1 (high).
Description
ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable an authenticated user to access unauthorized data stored within the Now Platform that the user otherwise would not be entitled to access. This issue is addressed in the listed patches and family release, which have been made available to hosted and self-hosted customers, as well as partners.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Now PlatformBrowse ServiceNow / Now PlatformDefault status: unaffected | CVE List | Before Washington DC Patch 9 | affected |
| Before Xanadu Patch 4 | affected | ||
| Before Yokohama | affected |
References
2support.servicenow.com
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1948695