CVE-2025-7371

MEDIUM

Okta On-Premises Provisioning - Info Disclosure

Title source: llm
STIX 2.1

Description

Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by this vulnerability if the following preconditions are met: Local server running OPP agent with versions >=2.2.1 and <= 2.3.0, and User account has had an administrator-initiated password reset while using the affected versions.

Scores

CVSS v3 6.8
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
Okta/Okta On-Premises Provisioning Agent 2.2.1 - 2.3.1
Published Jul 22, 2025
Tracked Since Feb 18, 2026