PT-2025-16975 · Unknown · Omnissa Uag
Published
2025-04-17
·
Updated
2025-05-01
·
CVE-2025-25234
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Omnissa UAG (affected versions not specified)
Description
The issue is related to a Cross-Origin Resource Sharing (CORS) bypass, which could allow a malicious actor with network access to bypass administrator-configured CORS restrictions and gain access to sensitive networks. CORS is a security feature that restricts web pages from making requests to a different origin (domain, protocol, or port) than the one the web page was loaded from, preventing malicious scripts from making unauthorized requests on behalf of the user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omnissa Uag