Security Compliance

Why SolarWinds Security Event Manager (SEM) is not affected by CVE-2024-38828

This article explains why SolarWinds Security Event Manager (SEM) is not affected by CVE-2024-38828. SolarWinds Security Event Manager (SEM) does not use the affected method parameter “@RequestBody byte[]" and is not affected by this vulnerability.

First published date

5/5/2025 9:42 PM

Last published date

5/5/2025 9:42 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2024-38828.

CVE-2024-38828 is a vulnerability on Spring MVC controller methods with the “@RequestBody byte[]” method parameter, which are vulnerable to a DoS attack.

This issue affects Spring Framework from 5.3.0 through 5.3.41 Older, unsupported versions are also affected.

The vulnerability described in this CVE affects numerous software companies, but it does not impact Security Event Manager (SEM).

Product section

Security Event Manager

Cause

CVE-2024-38828

Resolution

This vulnerability affects only applications that meet all the prerequisites mentioned above.