Server-Side Request Forgery Vulnerability in Omnissa Workspace ONE UEM
CVE-2025-25229

5.4MEDIUM

Key Information:

Vendor

Omnissa

Vendor
CVE Published:
11 August 2025

What is CVE-2025-25229?

The Omnissa Workspace ONE UEM is plagued by a Server-Side Request Forgery (SSRF) vulnerability, which enables a malicious user with the required privileges to gain unauthorized access to sensitive internal system information. By exploiting this vulnerability, attackers may enumerate internal network resources, compromising the security of the network and its data.

Affected Version(s)

Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.10.0.10 or earlier

Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.6.0.34 or earlier

Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.2.0.29 or earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omnissa would like to thank Khristopher Tolbert of Maveris for reporting this issue to us.
.