Database Management

Why SolarWinds DPA is not affected by CVE-2024-38828

This article explains why SolarWinds Database Performance Monitor (DPA) is not affected by CVE-2024-38828.

First published date

2/7/2025 7:48 PM

Last published date

2/4/2026 12:16 AM

Overview

In 2024, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2024-38828 (© 2025 National Institute of Standards and Technology, available at nvd.nist.gov, obtained on February 7, 2025).

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

Product section

Database Performance Analyzer

Cause

CVE-2024-38828

Resolution

DPA does not use  Spring MVC controller methods with an @RequestBody byte[] method parameter. Therefore, DPA is not vulnerable to CVE-2024-38828.