CVE-2025-25234: High severity omnissa unified access gateway vulnerability
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25234?
CVE-2025-25234 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive networks.
How do I fix CVE-2025-25234?
To fix CVE-2025-25234, update Omnissa UAG to the latest version that addresses the CORS bypass vulnerability.
Who is affected by CVE-2025-25234?
Any users of Omnissa UAG with misconfigured CORS settings may be affected by CVE-2025-25234.
What is the impact of CVE-2025-25234?
The impact of CVE-2025-25234 allows a malicious actor to bypass CORS restrictions, potentially accessing sensitive network resources.
Is CVE-2025-25234 easy to exploit?
Yes, CVE-2025-25234 is relatively easy to exploit if the attacker has network access to the UAG system.