CVE-2025-25234

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2025
Last modified:
21/04/2025

Description

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:omnissa:unified_access_gateway:*:*:*:*:*:*:*:* 2503 (excluding)