Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Omnissa Workspace ONE UEM version prior to 24.10.0.25
affected
Omnissa Workspace ONE UEM version prior to 24.6.0.44
affected
Omnissa Workspace ONE UEM version prior to 24.2.0.36
affected
Description
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.
Problem types
CWE-204 Observable Discrepancy Response
Product status
Omnissa Workspace ONE UEM version prior to 24.10.0.25
Omnissa Workspace ONE UEM version prior to 24.6.0.44
Omnissa Workspace ONE UEM version prior to 24.2.0.36
References
static.omnissa.com/sites/default/files/OMSA-2025-0005.pdf
www.omnissa.com/omnissa-security-response/