PT-2025-50553 · Okta · Okta Java Management Sdk

Published

2025-12-10

·

Updated

2025-12-12

·

CVE-2025-67505

CVSS v3.1

8.4

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Okta Java Management SDK versions 11.0.0 through 20.0.0
Description The Okta Java Management SDK, used for interacting with the Okta management API, is susceptible to race conditions when handling concurrent requests utilizing the ApiClient class. These race conditions can lead to a situation where the status code or response header from one request inadvertently affects another request’s response.
Recommendations Update to version 20.0.1 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2025-67505
GHSA-J5GQ-897M-2RFF

Affected Products

Okta Java Management Sdk