CVE-2025-25236
BaseFortify
Publication date: 2025-11-12
Last updated on: 2025-11-12
Assigner: Omnissa
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | workspace_one_uem | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Omnissa Workspace ONE UEM is an observable response discrepancy that allows a malicious actor to enumerate sensitive information such as tenant IDs and user accounts. This information can then be used to facilitate attacks like brute-force, password-spraying, or credential-stuffing.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access attempts by enabling attackers to gather sensitive information needed to perform brute-force, password-spraying, or credential-stuffing attacks, potentially compromising user accounts and tenant security.