CVE-2025-25234
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 21, 2025
CWE ID 942
Summary
CVE-2025-25234 is a newly identified vulnerability affecting Omnissa UAG. This issue allows a malicious actor with network access to Omnissa UAG to bypass administrator-configured Cross-Origin Resource Sharing (CORS) restrictions. By exploiting this vulnerability, attackers can gain unauthorized access to sensitive networks, potentially leading to data breaches and other security incidents. It is crucial that organizations using Omnissa UAG apply the necessary patches or mitigations to prevent exploitation of this CORS bypass vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Omnissa