Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34197
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34197.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-34197.
Product section
Cause
CVE-2026-34197 is an improper input validation and improper control of generation of code vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. This vulnerability requires authentication and a crafted discovery URI.
Resolution
While the component’s presence is flagged by dependency scanning tools, our analysis shows there is no associated security risk.
DPA is not affected by CVE-2026-34197, despite using a vulnerable ActiveMQ version. The attack vector, Jolokia JMX-HTTP bridge, does not exist in DPA's deployment.