CVE-2025-67505
Last modified
CVE-2025-67505 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Okta | Java Management Sdk | >= 11.0.0, < 20.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67505?
How severe is CVE-2025-67505?
How do I fix CVE-2025-67505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6750A vulnerability, which was classified as problematic, has be…3.3
- CVE-2025-67500Mastodon is a free, open-source social network server based …3.7
- CVE-2025-67501WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-67502Taguette is an open source qualitative research tool. In ver…6.1
- CVE-2025-67503Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2025-67504WBCE CMS is a content management system. Versions 1.6.4 and …9.8
- CVE-2025-67506PipesHub is a fully extensible workplace AI platform for ent…9.8
- CVE-2025-67507Filament is a collection of full-stack components for accele…8.1
- CVE-2025-67508gardenctl is a command-line client for the Gardener which co…8.4
- CVE-2025-67509Neuron is a PHP framework for creating and orchestrating AI …8.2
- CVE-2025-6751A vulnerability, which was classified as critical, was found…8.8
- CVE-2025-67510Neuron is a PHP framework for creating and orchestrating AI …9.4
Are you affected by CVE-2025-67505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
