Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-41254
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-41254.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-41254.
Product section
Cause
CVE-2025-41254 is a security bypass vulnerability affecting STOMP over WebSocket applications that utilize various versions of Spring Framework.
Resolution
This vulnerability requires an application to serve static resources using Spring’s resource handling such as ResourceWebHandler, @EnableWebMvc, or mvc:resources in XML config. Database Performance Analyzer (DPA) is not affected as it does not use any of the aforementioned tools.