Medium severity5.4NVD Advisory· Published Jan 31, 2025· Updated Apr 15, 2026
CVE-2025-22216
CVE-2025-22216
Description
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.