Vulnerability Description
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omnissa | Unified Access Gateway | < 2503 |
Related Weaknesses (CWE)
References
- https://static.omnissa.com/sites/default/files/OMSA-2025-0002.pdfVendor Advisory
- https://www.omnissa.com/omnissa-security-response/Vendor Advisory
FAQ
What is CVE-2025-25234?
CVE-2025-25234 is a vulnerability with a CVSS score of 7.1 (HIGH). Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain ...
How severe is CVE-2025-25234?
CVE-2025-25234 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25234?
Check the references section above for vendor advisories and patch information. Affected products include: Omnissa Unified Access Gateway.