Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
The product uses a cross-domain policy file that includes domains that should not be trusted.
Link | Tags |
---|---|
https://static.omnissa.com/sites/default/files/OMSA-2025-0002.pdf | vendor advisory |
https://www.omnissa.com/omnissa-security-response/ | vendor advisory |