Omnissa Workspace One CVE-2025-25231 Path Traversal Exploit
ID: aa054212-2927-5159-92bb-95a7029ec2f2
STIX ID: report--aa054212-2927-5159-92bb-95a7029ec2f2
Feed Name: Resources-2
Date Published: 2025-12-19
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
A critical vulnerability (CVE-2025-25231) in Omnissa Workspace ONE UEM's DevicesGateway allows unauthenticated attackers to perform secondary-context path traversal by manipulating the packageId parameter, enabling access to privileged internal endpoints, disclosure of administrative users, and escalation to Remote Code Execution via abuse of a hardcoded encryption master key and writable web-accessible blob cache paths; fixes are available in specified patched versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
