Database Management

Why SolarWinds Database Performance Analyzer is not affected by CVE-2025-48913

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2025-48913.

First published date

1/5/2026 5:17 PM

Last published date

1/5/2026 5:17 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-48913.

 

If untrusted users are allowed to configure JMS for Apache CXF, previously, they could use RMI or LDAP URLs to potentially lead to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3 to fix this issue.

Product section

Database Performance Analyzer

Cause

CVE-2025-48913

Resolution

This CVE is applicable when the application uses APACHE CXF JSM, and the issue arises only when untrusted users are allowed to configure JMS endpoints in Apache CXF.

SolarWinds DPA uses ActiveMQ for JMS; therefore, SolarWinds DPA is not affected.