CVE-2025-6083

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Jun 2025, 22:15

Type Values Removed Values Added
References
  • {'url': 'https://extreme-networks.my.site.com/', 'source': '1c053176-eef3-4d6a-ae0b-24728c86587b'}
  • () https://extreme-networks.my.site.com/ExtrArticleDetail?an=000126912 -
Summary (en) In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specfic owenr_id. (en) In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.

13 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-13 21:15

Updated : 2025-06-13 22:15


NVD link : CVE-2025-6083

Mitre link : CVE-2025-6083

CVE.ORG link : CVE-2025-6083


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication