CVE-2025-25231: Path Traversal
Published Aug 11, 2025
·Updated
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.
Affected Software
1 affected component
VMware Workspace ONE UEM
Event History
Aug 11, 2025
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-25231?
CVE-2025-25231 is considered a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2025-25231?
To address CVE-2025-25231, apply security patches provided by VMware for Workspace ONE UEM.
3
What type of vulnerability is CVE-2025-25231?
CVE-2025-25231 is a Secondary Context Path Traversal Vulnerability.
4
What can a malicious actor achieve by exploiting CVE-2025-25231?
Exploiting CVE-2025-25231 may allow a malicious actor to access sensitive information through crafted GET requests.
5
Which software is affected by CVE-2025-25231?
CVE-2025-25231 affects VMware Workspace ONE UEM.