Security Compliance

Security Event Manager is not affected by CVE-2024-38808

This article explains why SEM is not affected by CVE-2024-46589.

First published date

9/16/2024 8:32 PM

Last published date

4/3/2025 6:38 AM

Overview

In August of 2024, the National Institute of Standards and Technology (NIST) updated the security bulletin about CVE-2024-38808. Versions of the Spring Framework with this vulnerability could generate a denial of service (DoS) condition with a specially crafted Spring Expression Language (SpEL) expression when user-supplied SpEL expressions are evaluated.

Product section

Security Event Manager

Cause

CVE-2024-38808

Resolution

SEM includes SpELs primarily used for authorization checks. However, this vulnerability does not apply to SEM because SEM does not evaluate user-supplied SpELs.