Description
Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources.
Product status
Omnissa Workspace ONE UEM version 24.10.0.10 or earlier
Omnissa Workspace ONE UEM version 24.6.0.34 or earlier
Omnissa Workspace ONE UEM version 24.2.0.29 or earlier
Omnissa Workspace ONE UEM version 23.10.0.49 or earlier
Credits
Omnissa would like to thank Khristopher Tolbert of Maveris for reporting this issue to us.
References
www.omnissa.com/omsa-2025-0004/
www.omnissa.com/omnissa-security-response/