PT-2025-16975 · Unknown · Omnissa Uag

Published

2025-04-17

·

Updated

2025-05-01

·

CVE-2025-25234

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Omnissa UAG (affected versions not specified)
Description The issue is related to a Cross-Origin Resource Sharing (CORS) bypass, which could allow a malicious actor with network access to bypass administrator-configured CORS restrictions and gain access to sensitive networks. CORS is a security feature that restricts web pages from making requests to a different origin (domain, protocol, or port) than the one the web page was loaded from, preventing malicious scripts from making unauthorized requests on behalf of the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-25234

Affected Products

Omnissa Uag