National CSIRT-CY | National Computer Security Incident Response Team of Cyprus

Η Εθνική Ομάδα Αντιμετώπισης Ηλεκτρονικών Επιθέσεων προβλέπει την αύξηση της ηλεκτρονικής ασφαλείας ενισχύοντας την προστασία του κυβερνοχώρου των Εθνικών Κρίσιμων Πληροφοριακών Υποδομών, των τραπεζών και των παροχών επικοινωνίας της Κυπριακής Δημοκρατίας.

Secondary Context Path Traversal Vulnerability

19 September 2025

The Digital Security Authority (DSA) wants to bring to your attention a vulnerability affecting Secondary Context Path Traversal. 

 

Technical Details

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within

the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

 

Recommendations

The Digital Security Authority recommends to perform the necessary mitigation steps that can be found in Omnissa site here.

 

References

  1. Common Vulnerabilities & Exposures
  2. Common Weakness Enumeration

 

The information presented in this report is based on available data up to the 15th of September 2025. 

 [ Get the report  in .PDF ]

 

Cyber threats require heightened defences

Working towards a trusted and cyber secure Europe

Protect your cyber hygiene

Cyber Europe 2022 [exercise]