Home

Description

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.

PUBLISHED Reserved 2025-02-04 | Published 2025-04-17 | Updated 2025-04-17 | Assigner Omnissa




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Product status

Default status
unaffected

Omnissa Unified Access Gateway 2412 or earlier
affected

References

static.omnissa.com/sites/default/files/OMSA-2025-0002.pdf

www.omnissa.com/omnissa-security-response/

cve.org (CVE-2025-25234)

nvd.nist.gov (CVE-2025-25234)

Download JSON