CVE-2025-25231

HIGH EXPLOITED NUCLEI

Omnissa Workspace ONE UEM - Path Traversal

Title source: nuclei

Description

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

Exploits (1)

nomisec SCANNER
by ashkan-pu · infoleak
https://github.com/ashkan-pu/CVE-CVE-2025-25231

Nuclei Templates (1)

Omnissa Workspace ONE UEM - Path Traversal
HIGHVERIFIEDby DhiyaneshDK,slcyber
Shodan: html:"/airwatch/default.aspx"
FOFA: banner="/airwatch/default.aspx" || header="/airwatch/default.aspx"

Scores

CVSS v3 7.5
EPSS 0.0395
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-09-09
ENISA EUVD EUVD-2025-24160
CWE
CWE-22
Status published
Products (4)
Omnissa/Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 23.10.0.49 or earlier
Omnissa/Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.10.0.10 or earlier
Omnissa/Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.2.0.29 or earlier
Omnissa/Omnissa Workspace ONE UEM Omnissa Workspace ONE UEM version 24.6.0.34 or earlier
Published Aug 11, 2025
Tracked Since Feb 18, 2026