Back to Database
Status published
High
CVE-2025-25235
Omnissa Secure Email Gateway (SEG) updates address Server-Side Request Forgery (SSRF) vulnerability
Vulnerability Description
Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25235
Credits & Attribution
No credits recorded in the NVD database.
References
More from Omnissa
View All →CVE-2025-25236
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability....
Medium
5.3
CVE-2025-25234
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A...
High
7.1
CVE-2025-25231
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal...
High
7.5
CVE-2025-25230
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious...
High
7.8
CVE-2025-25229
Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF)...
Medium
5.4
Affected Vendor
Omnissa
View all reports →Affected Software
Secure Email Gateway
Vulnerable Versions:
2.32 and later, 2503 and later
Timeline
Official Publish:
August 11th, 2025
Last Modified:
August 12th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N