This article addresses inquiries regarding the impact of the Spring Framework security vulnerability, , on the Broadcom Identity Manager (IDM) product.
Broadcom Engineering has confirmed that Identity Manager is not vulnerable to CVE-2022-22950. The investigation determined the following:
No action is required for Identity Manager as it is not impacted by this vulnerability.
The Identity Suite has been designed with file upload size restrictions, as well as code validation, to prevent exactly this type of vulnerability from being exploited within the software.