Security Compliance

Why SolarWinds SEM is not affected by CVE-2024-38816 or CVE-2024-38819

This article explains why SolarWinds SEM is not affected by path traversal vulnerabilities (CVE-2024-38816 and CVE-2024-38816 .

First published date

11/21/2024 2:34 PM

Last published date

12/9/2025 5:05 PM

Overview

In 2024, Spring Security Advisories published the following security bulletins about vulnerabilities in the functional web frameworks WebMvc.fn or WebFlux.fn prior to 2024 Q3 (5.3.0 - 5.3.40, 6.0.0 - 6.0.24, 6.1.0 - 6.1.13, and older unsupported versions):

  • CVE-2024-38816 
    In the Spring Framework 5.3.0 - 5.3.39, 6.0.0 - 6.0.23, 6.1.0 - 6.1.12, and older, unsupported versions, applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks.  

  • CVE- 2024-38819  
    In the functional web frameworks WebMvc.fn or WebFlux.fn prior to 2024 Q3 (versions 5.3.0 - 5.3.40, 6.0.0 - 6.0.24, 6.1.0 - 6.1.13, and older unsupported versions), applications serving static resources are vulnerable to path traversal attacks.

The vulnerability described in these CVEs impacts numerous software companies.

Product section

Security Event Manager

Cause

CVE-2024-38816 and CVE-2024-38819

Resolution

CVE-2024-38816 and CVE-2024-38819 apply only to applications that use functional endpoints in the web frameworks WebMvc.fn or WebFlux.fn. In SEM, functional endpoints are not used in the product. Therefore, SEM is not vulnerable to these CVEs.