Security Compliance
Why SolarWinds SEM is not affected by CVE-2024-38816 or CVE-2024-38819
This article explains why SolarWinds SEM is not affected by path traversal vulnerabilities (CVE-2024-38816 and CVE-2024-38816 .
First published date
Last published date
Overview
In 2024, Spring Security Advisories published the following security bulletins about vulnerabilities in the functional web frameworks WebMvc.fn or WebFlux.fn prior to 2024 Q3 (5.3.0 - 5.3.40, 6.0.0 - 6.0.24, 6.1.0 - 6.1.13, and older unsupported versions):
-
CVE-2024-38816
In the Spring Framework 5.3.0 - 5.3.39, 6.0.0 - 6.0.23, 6.1.0 - 6.1.12, and older, unsupported versions, applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. - CVE- 2024-38819
In the functional web frameworks WebMvc.fn or WebFlux.fn prior to 2024 Q3 (versions 5.3.0 - 5.3.40, 6.0.0 - 6.0.24, 6.1.0 - 6.1.13, and older unsupported versions), applications serving static resources are vulnerable to path traversal attacks.
The vulnerability described in these CVEs impacts numerous software companies.
Product section
Cause
CVE-2024-38816 and CVE-2024-38819
Resolution
CVE-2024-38816 and CVE-2024-38819 apply only to applications that use functional endpoints in the web frameworks WebMvc.fn or WebFlux.fn. In SEM, functional endpoints are not used in the product. Therefore, SEM is not vulnerable to these CVEs.