Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Java Management Sdk HIGH 8.4
CVE-2025-67505

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from con…

Fix: 20.0.1+
Fix from $1,950 2025-12-10
Java Management Sdk MEDIUM 5.3
CVE-2025-66033

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementat…

Fix: 24.0.1+
Fix from $1,600 2025-12-10
Verify HIGH 7.8
CVE-2024-9191

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers …

Fix: 5.3.3+
Fix from $1,950 2024-11-01
Verify HIGH 7.8
CVE-2024-7061

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.…

Fix: 5.0.2+
Fix from $1,950 2024-08-07
Ldap Agent MEDIUM 6.7
CVE-2023-0392

The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.

Fix: 5.18+
Fix from $1,600 2023-11-08
Imprivata Privileged Access Management MEDIUM 5.4
CVE-2021-45094

Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.

No fix yet
Fix from $1,600 2023-07-20
Advanced Server Access HIGH 8.8
CVE-2023-0093

Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An o…

Fix: 1.68.2+
Fix from $1,950 2023-03-06
Advanced Server Access HIGH 8.8
CVE-2022-1030

Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafte…

Fix: 1.58.0+
Fix from $1,950 2022-03-23
Advanced Server Access Client For Windows HIGH 8.8
CVE-2022-24295EPSS 17%

Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

Fix: 1.57.0+
Fix from $1,950 2022-02-21
Access Gateway MEDIUM 6.7
CVE-2021-28113EPSS 22%

A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin …

Fix: after 2020.8.4
Fix from $1,600 2021-04-02