
- A mishap in ServiceNow access control lists meant users could be granted access, without meeting all the conditions
- New controls were added to mitigate the risk
- Users are advised to review their tables and ACLs
A flaw in ServiceNow could have allowed threat actors to exfiltrate sensitive data from other user’s tables without them ever knowing, security experts have warned.