CVE-2025-25231
largeUnauthenticated Path Traversal in Omnissa Workspace ONE UEM API
Omnissa Workspace ONE UEM (formerly VMware Workspace ONE) contains a secondary context path traversal vulnerability (CWE-22), tracked as CVE-2025-25231. A remote attacker needs no credentials and no user interaction: crafted, read-only GET requests sent to restricted API endpoints can use path traversal to reach resources outside the intended context. The attacker gains read access to sensitive information (CVSS confidentiality impact is high, with no integrity or availability impact). Any organization running Workspace ONE UEM is affected, with risk concentrated in deployments whose console or API endpoints are reachable over the network, including from the internet. As of now the flaw is not in CISA's KEV, no public proof-of-concept is known, and exploitation has not been confirmed, although the EPSS score of 21.3% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.
What to do: Check Omnissa's security advisory for CVE-2025-25231 to identify your affected version ranges and apply the patched release (specific fixed versions are not listed in this CVE record). Until patched, restrict network access to Workspace ONE UEM console and API endpoints via firewall allowlisting or a WAF, and review access logs for anomalous unauthenticated GET requests against restricted API paths. Because the impact is read-only information disclosure, investigate for exposure and rotate any credentials, keys, or secrets that may have been retrievable through the console API.
| Omnissa Workspace ONE UEM | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.