Observability

Why SolarWinds Observability Self-Hosted and Access Rights Manager is not affected by CVE-2025-15467

This article explains why SolarWinds Observability Self-Hosted and Access Rights Manager are not affected by CVE-2025-15467.

First published date

2/10/2026 7:38 PM

Last published date

4/2/2026 5:23 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-15467.

Product section

Hybrid Cloud Observability

Cause

CVE-2025-15467, a stack buffer overflow vulnerability in OpenSSL that could lead to denial-of-service or remote code execution.

Resolution

This CVE is exploitable when the application parses CMS AuthEnvelopedData message with maliciously crafted AEAD parameters.

SolarWinds uses OpenSSL to support SSL, SSH, and TLS communication, and database connections are generally not affected.