Observability
Why SolarWinds Observability Self-Hosted and Access Rights Manager is not affected by CVE-2025-15467
This article explains why SolarWinds Observability Self-Hosted and Access Rights Manager are not affected by CVE-2025-15467.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-15467.
Product section
Cause
CVE-2025-15467, a stack buffer overflow vulnerability in OpenSSL that could lead to denial-of-service or remote code execution.
Resolution
This CVE is exploitable when the application parses CMS AuthEnvelopedData message with maliciously crafted AEAD parameters.
SolarWinds uses OpenSSL to support SSL, SSH, and TLS communication, and database connections are generally not affected.