Permissive Cross-domain Policy with Untrusted Domains
CVE-2025-25234
Summary
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
- LOW
- NETWORK
- LOW
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- NONE
CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
The software uses a cross-domain policy file that includes domains that should not be trusted.
References
Advisory Timeline
- Published