Network Management
Why SolarWinds Observability Self-Hosted and Database Performance Analyzer is not affected by CVE-2025-68161
This article explains why SolarWinds Observability Self-Hosted and Database Performance Analyzer is not affected by CVE-2025-68161.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-68161.
Product section
Cause
CVE-2025-68161
Resolution
SolarWinds Observability Self-Hosted and Database Performance Analyzer do not utilize the Apache Log4j Socket Appender; therefore, SolarWinds Observability Self-Hosted and Database Performance Analyzer are not affected.
-
- The vulnerability only applies when the Apache Log4j Socket Appender over TLS is configured and in use.
- DPA does not utilize the Apache Log4j Socket Appender, so the vulnerable code path is never invoked.
-
Libraries are present, but the vulnerable configuration is absent
- Log4j API/core JARs (including log4j-core-2.17.1.jar) are present as part of the product, but they are used without the Socket Appender configuration referenced in the CVE.
- Because the prerequisite configuration is missing, scanners are flagging this purely on version detection, not on an exploitable logging setup.