Race condition in Jersey - CVE-2025-12383
Published: January 20, 2026 / Updated: February 3, 2026
Vulnerability identifier: #VU121703
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12383
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass trust restrictions.
The vulnerability exists due to a race condition in the SSL/TLS configuration handling. A remote attacker can bypass trust restrictions and gain unauthorized access to the application.
Affected software
Jersey
Storage Defender Copy Data Management
OpenPages for IBM Cloud Pak for Data
DevOps
IBM Engineering Lifecycle Optimization - Publishing
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
MongoDB Enterprise Advanced with IBM
Storage Protect Server
watsonx.data
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM UrbanCode Release
Bamboo Server
IBM Cloud Pak for Business Automation
RSA Authentication Manager
Oracle WebLogic Server
Oracle SOA Suite
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Database Server
Oracle Communications Cloud Native Core Policy
Operational Decision Manager
Storage Defender Copy Data Management
OpenPages for IBM Cloud Pak for Data
DevOps
IBM Engineering Lifecycle Optimization - Publishing
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
MongoDB Enterprise Advanced with IBM
Storage Protect Server
watsonx.data
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM UrbanCode Release
Bamboo Server
IBM Cloud Pak for Business Automation
RSA Authentication Manager
Oracle WebLogic Server
Oracle SOA Suite
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Database Server
Oracle Communications Cloud Native Core Policy
Operational Decision Manager
How to mitigate CVE-2025-12383
Install updates from vendor's website.
Jersey - addressed in versions 2.46, 3.0.17, 3.1.10, 4.0.0-M2
Storage Defender Copy Data Management - update to 2.2.28.0
watsonx.data - update to 2.3.1
OpenPages for IBM Cloud Pak for Data - update to 5.3.1
IBM Sterling External Authentication Server - update to 6.1.1.2
IBM Sterling Secure Proxy - update to 6.2.1.2
DevOps - update to 7.0.0.6
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.3.22, 7.1.0.9, 7.2.0.2
RSA Authentication Manager - update to 8.9 Patch 1
OpenPages Cloud pak for data service version - update to 9.6.1
Bamboo Server - addressed in versions 9.6.21, 10.2.13
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
MongoDB Enterprise Advanced with IBM - update to 8.0.17
Storage Protect Server - update to 8.2.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 54, 8.11.1 Interim fix 53, 8.12.0.1 Interim fix 37, 9.0.0.1 Interim fix 22, 9.5.0.1 Interim fix 5
Storage Defender Copy Data Management - update to 2.2.28.0
watsonx.data - update to 2.3.1
OpenPages for IBM Cloud Pak for Data - update to 5.3.1
IBM Sterling External Authentication Server - update to 6.1.1.2
IBM Sterling Secure Proxy - update to 6.2.1.2
DevOps - update to 7.0.0.6
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.3.22, 7.1.0.9, 7.2.0.2
RSA Authentication Manager - update to 8.9 Patch 1
OpenPages Cloud pak for data service version - update to 9.6.1
Bamboo Server - addressed in versions 9.6.21, 10.2.13
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
MongoDB Enterprise Advanced with IBM - update to 8.0.17
Storage Protect Server - update to 8.2.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 54, 8.11.1 Interim fix 53, 8.12.0.1 Interim fix 37, 9.0.0.1 Interim fix 22, 9.5.0.1 Interim fix 5
External References
Related Security Bulletins
- Race condition in Eclipse Jersey
- Multiple vulnerabilities in Oracle Database Server
- Race condition in Oracle Global Lifecycle Management NextGen OUI Framework
- Multiple vulnerabilities in Oracle WebLogic Server
- Bamboo Data Center update for org.glassfish.jersey.core:jersey-client
- IBM Sterling External Authentication Server update for Eclipse Jersey
- IBM Storage Defender Copy Data Management update for Eclipse Jersey
- MongoDB Enterprise Advanced with IBM update for Eclipse Jersey
- IBM OpenPages for Cloud Pak for Data update for Eclipse Jersey
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- IBM Sterling Secure Proxy update for Eclipse Jersey
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM watsonx.data update for Eclipse Jersey
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in IBM DevOps Release
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle SOA Suite
- IBM Engineering Lifecycle Optimization - Publishing update for Eclipse Jersey
- IBM Storage Protect Server update for Eclipse Jetty