CVE-2025-67505

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*

History

06 Mar 2026, 19:42

Type Values Removed Values Added
First Time Okta java Management Sdk
Okta
CPE cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*
References () https://github.com/okta/okta-sdk-java/commit/abf4f128a0441f90cb7efcdcf4bde1aef8703243 - () https://github.com/okta/okta-sdk-java/commit/abf4f128a0441f90cb7efcdcf4bde1aef8703243 - Patch
References () https://github.com/okta/okta-sdk-java/security/advisories/GHSA-j5gq-897m-2rff - () https://github.com/okta/okta-sdk-java/security/advisories/GHSA-j5gq-897m-2rff - Vendor Advisory

10 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 23:15

Updated : 2026-03-06 19:42


NVD link : CVE-2025-67505

Mitre link : CVE-2025-67505

CVE.ORG link : CVE-2025-67505


JSON object : View

Products Affected

okta

  • java_management_sdk
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')