Network Management

Why SolarWinds Observability Self-Hosted and Database Performance Analyzer is not affected by CVE-2025-68161

This article explains why SolarWinds Observability Self-Hosted and Database Performance Analyzer is not affected by CVE-2025-68161.

First published date

1/9/2026 9:22 PM

Last published date

5/8/2026 1:57 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-68161.

Product section

Orion Platform

Cause

CVE-2025-68161

 

 

Resolution

SolarWinds Observability Self-Hosted and Database Performance Analyzer do not utilize the Apache Log4j Socket Appender; therefore, SolarWinds Observability Self-Hosted and Database Performance Analyzer are not affected.

    • The vulnerability only applies when the Apache Log4j Socket Appender over TLS is configured and in use.
    • DPA does not utilize the Apache Log4j Socket Appender, so the vulnerable code path is never invoked.
  • Libraries are present, but the vulnerable configuration is absent

    • Log4j API/core JARs (including log4j-core-2.17.1.jar) are present as part of the product, but they are used without the Socket Appender configuration referenced in the CVE.
    • Because the prerequisite configuration is missing, scanners are flagging this purely on version detection, not on an exploitable logging setup.