Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-42498
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-42498.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-42498.
Product section
Cause
CVE-2026-42498 is an exposure of HTTP authentication header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
Resolution
Database Performance Analyzer (DPA) does not use Tomcat WebSocket client to make outbound connections and is therefore not affected by the vulnerability.