Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-41254

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-41254.

First published date

5/6/2026 9:38 PM

Last published date

5/6/2026 9:38 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-41254.

Product section

Database Performance Analyzer

Cause

CVE-2025-41254 is a security bypass vulnerability affecting STOMP over WebSocket applications that utilize various versions of Spring Framework.

Resolution

This vulnerability requires an application to serve static resources using Spring’s resource handling such as ResourceWebHandler, @EnableWebMvc, or mvc:resources in XML config. Database Performance Analyzer (DPA) is not affected as it does not use any of the aforementioned tools.