Security Compliance

Why SolarWinds DPA, SEM, and WHD are not affected by CVE-2024-50379 and CVE-2024-56337

This article explains why SolarWinds Database Performance Monitor (DPA), Security Event Manager (SEM), and Web Help Desk (WHD) are not affected by CVE-2024-50379 and CVE-2024-56337.

First published date

12/26/2024 4:02 PM

Last published date

1/12/2026 10:28 PM

Overview

In 2024, the National Institute of Standards and Technology (NIST) published security bulletins about CVE-2024-50379 (© 2024 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on December 20, 2024) and CVE-2024-56337 (© 2025 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on January 17, 2025).

Both CVEs are a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat that permits an RCE on case insensitive file systems when the default servlet is enabled for write (which is a non-default configuration). This issue affects Apache Tomcat from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.

The vulnerability described in these CVEs affects numerous software companies.

Product section

Security Event Manager

Cause

CVE-2024-50379 and CVE-2024-56337

Resolution

These vulnerabilities affect only applications that change the value of the readonly init parameter to false, which makes the default servlet write enabled. DPA, SEM, and WHD do not change this value. Therefore, DPA, SEM, and WHD are not vulnerable to CVE-2024-50379 or CVE-2024-56337.