PT-2025-50545 · Okta · Okta Java Management Sdk

Published

2025-12-10

·

Updated

2025-12-12

·

CVE-2025-66033

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Okta Java Management SDK versions 21.0.0 through 24.0.0
Description The Okta Java Management SDK, used for interacting with the Okta management API, has a potential issue in multithreaded implementations. Versions 21.0.0 through 24.0.0 may experience memory issues due to improper thread cleanup after requests. This can lead to performance degradation and availability issues in long-running applications, potentially resulting in a denial-of-service condition under sustained load. Applications utilizing the ApiClient in a multithreaded manner are particularly at risk.
Recommendations Update to version 24.0.1 or later.

Exploit

Fix

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2025-66033
GHSA-QHR6-6CGV-6638

Affected Products

Okta Java Management Sdk