Database Management
Why SolarWinds DPA is not affected by CVE-2024-38828
This article explains why SolarWinds Database Performance Monitor (DPA) is not affected by CVE-2024-38828.
First published date
Last published date
Overview
In 2024, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2024-38828 (© 2025 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on February 7, 2025).
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
Product section
Cause
CVE-2024-38828
Resolution
DPA does not use Spring MVC controller methods with an @RequestBody byte[] method parameter. Therefore, DPA is not vulnerable to CVE-2024-38828.