Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-48976

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-48976.

First published date

5/6/2026 9:41 PM

Last published date

5/6/2026 9:41 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-48976.

Product section

Database Performance Analyzer

Cause

CVE-2025-48976 is a denial of service (DoS) vulnerability affecting Apache Commons FileUpload. This is due to the allocation of resources for multipart headers with insufficient limits.

Resolution

Database Performance Analyzer (DPA) is not vulnerable because it does not utilize Apache Commons FileUpload or any code path of this vulnerability.