Home

Description

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.

PUBLISHED Reserved 2025-02-04 | Published 2025-11-12 | Updated 2025-11-12 | Assigner Omnissa




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-204 Observable Discrepancy Response

Product status

Default status
unaffected

Omnissa Workspace ONE UEM version prior to 24.10.0.25
affected

Omnissa Workspace ONE UEM version prior to 24.6.0.44
affected

Omnissa Workspace ONE UEM version prior to 24.2.0.36
affected

References

static.omnissa.com/sites/default/files/OMSA-2025-0005.pdf

www.omnissa.com/omnissa-security-response/

cve.org (CVE-2025-25236)

nvd.nist.gov (CVE-2025-25236)

Download JSON