Security Compliance
Why SolarWinds Security Event Manager (SEM) is not affected by CVE-2024-38828
This article explains why SolarWinds Security Event Manager (SEM) is not affected by CVE-2024-38828. SolarWinds Security Event Manager (SEM) does not use the affected method parameter “@RequestBody byte[]" and is not affected by this vulnerability.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2024-38828.
CVE-2024-38828 is a vulnerability on Spring MVC controller methods with the “@RequestBody byte[]” method parameter, which are vulnerable to a DoS attack.
This issue affects Spring Framework from 5.3.0 through 5.3.41 Older, unsupported versions are also affected.
The vulnerability described in this CVE affects numerous software companies, but it does not impact Security Event Manager (SEM).
Product section
Cause
CVE-2024-38828
Resolution
This vulnerability affects only applications that meet all the prerequisites mentioned above.