Server-Side Request Forgery Vulnerability in Omnissa Workspace ONE UEM
CVE-2025-25229
5.4MEDIUM
What is CVE-2025-25229?
The Omnissa Workspace ONE UEM is plagued by a Server-Side Request Forgery (SSRF) vulnerability, which enables a malicious user with the required privileges to gain unauthorized access to sensitive internal system information. By exploiting this vulnerability, attackers may enumerate internal network resources, compromising the security of the network and its data.
Affected Version(s)
Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.10.0.10 or earlier
Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.6.0.34 or earlier
Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.2.0.29 or earlier
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Omnissa would like to thank Khristopher Tolbert of Maveris for reporting this issue to us.