CVE-2025-25236: Medium severity VMware Workspace ONE UEM vulnerability
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25236?
CVE-2025-25236 has been rated as a high-severity vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2025-25236?
To mitigate CVE-2025-25236, ensure that you are using the latest version of VMware Workspace ONE UEM and apply any relevant security patches provided by VMware.
What are the risks associated with CVE-2025-25236?
CVE-2025-25236 can allow attackers to enumerate sensitive information, leading to potential brute-force or credential-stuffing attacks.
Does CVE-2025-25236 affect all versions of VMware Workspace ONE UEM?
CVE-2025-25236 specifically impacts the versions of VMware Workspace ONE UEM that have not been patched against this vulnerability.
What causes the CVE-2025-25236 vulnerability?
CVE-2025-25236 is caused by an observable response discrepancy that allows unauthorized users to infer sensitive data.