CVE-2025-22216

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 384

Summary

CVE-2025-22216 is a vulnerability affecting UAA (UmaApi and OAuth Servers) systems with multiple identity zones. The issue arises due to insufficient session validation between zones. As a result, a user authenticated through a corporate IDP may reuse their jsessionid to gain unauthorized access to other zones. This vulnerability could lead to serious data breaches or unauthorized system access. It is strongly recommended to update the UAA system to address this issue promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share