Race condition in Jersey - CVE-2025-12383

 

Race condition in Jersey - CVE-2025-12383

Published: January 20, 2026 / Updated: February 3, 2026


Vulnerability identifier: #VU121703
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12383
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass trust restrictions.

The vulnerability exists due to a race condition in the SSL/TLS configuration handling. A remote attacker can bypass trust restrictions and gain unauthorized access to the application. 


Affected software

Jersey
Storage Defender Copy Data Management
OpenPages for IBM Cloud Pak for Data
DevOps
IBM Engineering Lifecycle Optimization - Publishing
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
MongoDB Enterprise Advanced with IBM
Storage Protect Server
watsonx.data
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM UrbanCode Release
Bamboo Server
IBM Cloud Pak for Business Automation
RSA Authentication Manager
Oracle WebLogic Server
Oracle SOA Suite
Oracle Global Lifecycle Management NextGen OUI Framework
Oracle Database Server
Oracle Communications Cloud Native Core Policy
Operational Decision Manager

How to mitigate CVE-2025-12383

Install updates from vendor's website.

Jersey - addressed in versions 2.46, 3.0.17, 3.1.10, 4.0.0-M2
Storage Defender Copy Data Management - update to 2.2.28.0
watsonx.data - update to 2.3.1
OpenPages for IBM Cloud Pak for Data - update to 5.3.1
IBM Sterling External Authentication Server - update to 6.1.1.2
IBM Sterling Secure Proxy - update to 6.2.1.2
DevOps - update to 7.0.0.6
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.3.22, 7.1.0.9, 7.2.0.2
RSA Authentication Manager - update to 8.9 Patch 1
OpenPages Cloud pak for data service version - update to 9.6.1
Bamboo Server - addressed in versions 9.6.21, 10.2.13
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
MongoDB Enterprise Advanced with IBM - update to 8.0.17
Storage Protect Server - update to 8.2.2
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 54, 8.11.1 Interim fix 53, 8.12.0.1 Interim fix 37, 9.0.0.1 Interim fix 22, 9.5.0.1 Interim fix 5

External References

Related Security Bulletins