Security Compliance
Why SolarWinds DPA, SEM, and WHD are not affected by CVE-2024-50379 and CVE-2024-56337
This article explains why SolarWinds Database Performance Monitor (DPA), Security Event Manager (SEM), and Web Help Desk (WHD) are not affected by CVE-2024-50379 and CVE-2024-56337.
First published date
Last published date
Overview
In 2024, the National Institute of Standards and Technology (NIST) published security bulletins about CVE-2024-50379 (© 2024 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on December 20, 2024) and CVE-2024-56337 (© 2025 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on January 17, 2025).
Both CVEs are a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat that permits an RCE on case insensitive file systems when the default servlet is enabled for write (which is a non-default configuration). This issue affects Apache Tomcat from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97.
The vulnerability described in these CVEs affects numerous software companies.
Product section
Cause
CVE-2024-50379 and CVE-2024-56337
Resolution
These vulnerabilities affect only applications that change the value of the readonly init parameter to false, which makes the default servlet write enabled. DPA, SEM, and WHD do not change this value. Therefore, DPA, SEM, and WHD are not vulnerable to CVE-2024-50379 or CVE-2024-56337.