logo

Omnissa Workspace One CVE-2025-25231 Path Traversal Exploit

ID: aa054212-2927-5159-92bb-95a7029ec2f2

STIX ID: report--aa054212-2927-5159-92bb-95a7029ec2f2

Feed Name: Resources-2

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

A critical vulnerability (CVE-2025-25231) in Omnissa Workspace ONE UEM's DevicesGateway allows unauthenticated attackers to perform secondary-context path traversal by manipulating the packageId parameter, enabling access to privileged internal endpoints, disclosure of administrative users, and escalation to Remote Code Execution via abuse of a hardcoded encryption master key and writable web-accessible blob cache paths; fixes are available in specified patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.